Junglewise Threat Intelligence

CVE-2026-57211: RabbitMQ SSRF and path traversal in management plugin on Windows

CVE-2026-57211 · Severity: medium · CVSS 6.5 · Published 2026-07-10

Technologies: RabbitMQ. Vendors: RabbitMQ.

Executive brief

RabbitMQ is a widely used messaging broker that facilitates communication between different software applications. A vulnerability in its management interface on Windows allows attackers to trick the system into making unauthorized connections to external servers. This could lead to the disclosure of sensitive information, such as internal network details or authentication credentials, potentially compromising the security of the host environment.

Technical details

A Server-Side Request Forgery (SSRF) and absolute path traversal vulnerability exists in the RabbitMQ management plugin's static file handler (`rabbit_mgmt_wm_static`) when running on Windows. When multiple management extension plugins are enabled, the handler fails to properly validate paths containing URL-encoded backslashes before passing them to the `erl_prim_loader:read_file_info` function. An unauthenticated remote attacker can exploit this by sending specially crafted requests that include UNC paths, forcing the server to initiate outbound DNS and SMB requests to an attacker-controlled infrastructure. This can be used to leak NTLM hashes or perform internal network reconnaissance. The issue is resolved in versions 4.1.11 and 4.2.6 by applying path filtering earlier in the request lifecycle.

Affected products

  • RabbitMQ RabbitMQ >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6

Timeline

  • 2026-03-23: patched: Initial fix committed to main branch
  • 2026-04-23: advisory: Release of version 4.2.6
  • 2026-06-18: disclosed: GitHub Security Advisory published
  • 2026-07-10: advisory: NVD publication date

References