Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-9133

Опубликовано: 20 мая 2026
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.

To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.

EPSS

Процентиль: 27%
0.00344
Низкий

7.7 High

CVSS3

Дефекты

CWE-489

EPSS

Процентиль: 27%
0.00344
Низкий

7.7 High

CVSS3

Дефекты

CWE-489