Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57217

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 6.5

Описание

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

A flaw was found in RabbitMQ, a messaging and streaming broker. During metadata-store failures, the topic authorization mechanism can incorrectly allow restricted topic writes and binds. This occurs because permission lookup errors from Khepri are treated as an 'allow' condition by the internal backend. This vulnerability could enable an attacker to bypass intended topic restrictions, potentially leading to unauthorized message manipulation or access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1FixedRHSA-2026:3593906.07.2026
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1FixedRHSA-2026:3594006.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2499210rabbitmq: RabbitMQ: Authorization bypass allows unauthorized topic writes and binds during metadata-store failures

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
nvd
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
msrc
около 2 месяцев назад

RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

CVSS3: 6.5
debian
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21 ...

github
3 месяца назад

Topic authorization can lead to cross-tenant routing-key bypass

6.5 Medium

CVSS3