Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-57218

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

A flaw was found in RabbitMQ. An existing consumer in RabbitMQ AMQP 0-9-1 can continue to receive messages even after its OAuth token has expired or its connection's scopes have been reduced. This occurs because consumers are not properly canceled or reauthorized when the channel user state changes, potentially leading to unauthorized information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 16.2rabbitmq-serverNot affected
Red Hat OpenStack Platform 17.1rabbitmq-serverNot affected
Red Hat OpenStack Platform 18.0rabbitmq-serverNot affected
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1FixedRHSA-2026:3593906.07.2026
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1FixedRHSA-2026:3594006.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2499212rabbitmq-server: RabbitMQ: Information disclosure due to improper consumer reauthorization

EPSS

Процентиль: 45%
0.00565
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

CVSS3: 6.5
nvd
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

CVSS3: 6.5
debian
2 месяца назад

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ ...

github
3 месяца назад

AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure

EPSS

Процентиль: 45%
0.00565
Низкий

6.5 Medium

CVSS3