RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
ID: e9093c22-e9f4-501a-8e8c-c7c071477d44
STIX ID: report--e9093c22-e9f4-501a-8e8c-c7c071477d44
Feed Name: The Hacker News
Cybersecurity researchers disclosed two access-control vulnerabilities in RabbitMQ that can lead to severe impact: CVE-2026-57219 can leak the management OAuth client secret (allowing token exchange and full broker takeover where that secret is used), and CVE-2026-57221 permits authenticated users to enumerate queues and read tenant message/consumer counts; affected releases date from 3.13.0 onwards and vendors have published fixes and mitigation guidance (rotate secrets, restrict management access, patch to listed versions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
