VYPR
High severity7.5NVD Advisory· Published Jul 10, 2026· Updated Jul 29, 2026

CVE-2026-57219

CVE-2026-57219

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected products

2

Patches

Vulnerability mechanics

References

6

News mentions

3