Junglewise Threat Intelligence

CVE-2026-57215: RabbitMQ incorrect authorization in amq.rabbitmq.reply-to bindings

CVE-2026-57215 · Severity: info · CVSS 7 · Published 2026-07-10

Technologies: Broadcom Rabbitmq Server. Vendors: RabbitMQ, Broadcom.

Executive brief

RabbitMQ is a widely used message broker that facilitates communication between different software applications. A vulnerability in certain versions allows unauthorized users to create persistent message routing entries to internal 'reply-to' destinations that should be temporary. This could allow an attacker to intercept or redirect private application responses, potentially leading to the exposure of sensitive data or disruption of service operations.

Technical details

RabbitMQ is vulnerable to an incorrect authorization flaw (CWE-863) where it allows foreign bindings to 'amq.rabbitmq.reply-to' destinations. The root cause is that volatile direct-reply-to queues are accepted at bind and route time but are omitted from Khepri-backed deletion checks. This results in persistent route entries remaining in the system even after an unbind operation. An attacker with low-privileged network access can exploit this to establish unauthorized bindings, potentially intercepting messages intended for other clients. The issue is fixed in RabbitMQ versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.

Affected products

  • RabbitMQ RabbitMQ Server >= 3.13.0, < 3.13.15; >= 4.0.0, < 4.0.21; >= 4.1.0, < 4.1.11; >= 4.2.0, < 4.2.6

Timeline

  • 2026-04-05: patched: Initial fix committed to main branch
  • 2026-07-10: disclosed: CVE published and advisory released

References

Related threats