Medium severity6.5NVD Advisory· Published Feb 12, 2026· Updated Jun 17, 2026
CVE-2026-25768
CVE-2026-25768
Description
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cloudamqp/lavinmqv5Range: < 2.6.6
Patches
Vulnerability mechanics
References
3- github.com/cloudamqp/lavinmq/commit/e871f8d0a53685f04e39e6410a2421c1f82803b0nvdPatch
- github.com/cloudamqp/lavinmq/pull/1669nvdIssue TrackingPatch
- github.com/cloudamqp/lavinmq/security/advisories/GHSA-r2mh-8vq6-qf7mnvdVendor Advisory
News mentions
0No linked articles in our index yet.