Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57217

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

A flaw was found in RabbitMQ, a messaging and streaming broker. During metadata-store failures, the topic authorization mechanism can incorrectly allow restricted topic writes and binds. This occurs because permission lookup errors from Khepri are treated as an 'allow' condition by the internal backend. This vulnerability could enable an attacker to bypass intended topic restrictions, potentially leading to unauthorized message manipulation or access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1FixedRHSA-2026:3593906.07.2026
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1FixedRHSA-2026:3594006.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2499210rabbitmq: RabbitMQ: Authorization bypass allows unauthorized topic writes and binds during metadata-store failures

EPSS

Процентиль: 28%
0.00352
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
nvd
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

CVSS3: 6.5
msrc
12 дней назад

RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

CVSS3: 6.5
debian
23 дня назад

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21 ...

github
около 1 месяца назад

Topic authorization can lead to cross-tenant routing-key bypass

EPSS

Процентиль: 28%
0.00352
Низкий

6.5 Medium

CVSS3