Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

CVE-2026-57219 — rabbitmq-server

Fix: rabbitmq/rabbitmq-server@98b1daf

CVE-2026-57219 is a Information Exposure vulnerability. A fix is available — see the affected versions and patch details below.

RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations

Also known asGHSA-pj24-8j6m-vq9q
Published
Updated
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 8, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-57219.

EPSS Exploitation Probability

via FIRST.org ↗
2.8%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs86th percentile — riskier than 86% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected Products

1 product · 1 configurations
Application
rabbitmq serverbroadcom
≥ 3.13.0 && < 4.2.6
range

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for CVE-2026-57219, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.

How to detect CVE-2026-57219

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id cve-2026-57219 -u https://target
Template
RabbitMQ Management - OAuth 2 Client Secret Disclosure
Severity
high
Impact
Unauthenticated attackers can access OAuth 2 client secrets, leading to credential exposure and potential unauthorized access.
Remediation
Update to versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 or later.

Template by ProjectDiscovery nuclei-templates (aryu-ru), MIT licensed. View the full template. Scan only systems you are authorised to test.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant
ProductFixed inAdvisory
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1RHSA-2026:35939
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1RHSA-2026:35940

Frequently Asked Questions

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
O3 Security · Impact-Aware SCA

Is CVE-2026-57219 in your dependencies?

Find it across , including transitive dependencies.

CVE-2026-57219: rabbitmq-server