PT-2026-57300 · Vmware+1 · Rabbitmq

CVE-2026-57215

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6
Description RabbitMQ allows foreign bindings to 'amq.rabbitmq.reply-to' destinations. This occurs because volatile direct-reply-to queues are accepted during bind and route operations but are omitted from Khepri-backed deletion checks, which results in persistent route entries remaining after an unbind operation.
Recommendations Update to version 3.13.15 Update to version 4.0.20 Update to version 4.1.11 Update to version 4.2.6

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92364
CVE-2026-57215
GHSA-5CQ3-V9JX-P3X3
RHSA-2026:35939
RHSA-2026:35940

Affected Products

Rabbitmq