Medium severity6.5NVD Advisory· Published Jul 10, 2026· Updated Jul 13, 2026
CVE-2026-57217
CVE-2026-57217
Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.
Affected products
3- Range: <3.13.15, <4.0.21, <4.1.11, <4.2.6
- Range: <3.13.15, <4.0.21, <4.1.11, <4.2.6
- cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*Range: >=3.13.0,<4.2.6
Patches
Vulnerability mechanics
References
6- github.com/rabbitmq/rabbitmq-server/commit/94f1d33a70fcfa09006649599e79fc92786a2d36nvdPatch
- github.com/rabbitmq/rabbitmq-server/commit/ce1f682aa6b398820c5e3ce1ff7435184027c82cnvdPatch
- github.com/rabbitmq/rabbitmq-server/pull/15941nvdIssue TrackingPatch
- github.com/rabbitmq/rabbitmq-server/pull/15943nvdIssue TrackingPatch
- github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-gpvw-75h5-3wvxnvdExploitVendor Advisory
- github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6nvdRelease Notes
News mentions
1- RabbitMQ: Nine Vulnerabilities Disclosed Together, Threatening Authentication and Data IntegrityVypr Intelligence · Jul 18, 2026