CVE-2026-57219 — rabbitmq-server
Fix: rabbitmq/rabbitmq-server@98b1dafCVE-2026-57219 is a Information Exposure vulnerability. A fix is available — see the affected versions and patch details below.
RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-57219.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Affected Products
rabbitmq serverbroadcomDetection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Fix
Upgrade the affected component to the fixed release for CVE-2026-57219, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.
Workarounds
Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.
How to detect CVE-2026-57219
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2026-57219 -u https://target- Template
- RabbitMQ Management - OAuth 2 Client Secret Disclosure
- Severity
- high
- Impact
- Unauthenticated attackers can access OAuth 2 client secrets, leading to credential exposure and potential unauthorized access.
- Remediation
- Update to versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 or later.
Template by ProjectDiscovery nuclei-templates (aryu-ru), MIT licensed. View the full template. Scan only systems you are authorised to test.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
| Product | Fixed in | Advisory |
|---|---|---|
| Red Hat Hardened Images | rabbitmq-server4-3-main-4.3.2-1.hum1 | RHSA-2026:35939 |
| Red Hat Hardened Images | rabbitmq-server4-2-main-4.2.8-1.hum1 | RHSA-2026:35940 |
Frequently Asked Questions
Is CVE-2026-57219 in your dependencies?
Find it across , including transitive dependencies.