CVE-2026-57218

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
Configurations

Configuration 1 (hide)

cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*

History

13 Jul 2026, 20:54

Type Values Removed Values Added
CPE cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*
References () https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4 - () https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4 - Patch
References () https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e - () https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e - Patch
References () https://github.com/rabbitmq/rabbitmq-server/pull/16092 - () https://github.com/rabbitmq/rabbitmq-server/pull/16092 - Issue Tracking, Patch
References () https://github.com/rabbitmq/rabbitmq-server/pull/16097 - () https://github.com/rabbitmq/rabbitmq-server/pull/16097 - Issue Tracking, Patch
References () https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 - () https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 - Release Notes
References () https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7 - () https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Broadcom
Broadcom rabbitmq Server

13 Jul 2026, 19:17

Type Values Removed Values Added
References () https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7 - () https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7 -

10 Jul 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 21:16

Updated : 2026-07-13 20:54


NVD link : CVE-2026-57218

Mitre link : CVE-2026-57218

CVE.ORG link : CVE-2026-57218


JSON object : View

Products Affected

broadcom

  • rabbitmq_server
CWE
CWE-863

Incorrect Authorization