Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
Not in CISA KEV

RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurationsGHSA-pj24-8j6m-vq9q

Fix: rabbitmq/rabbitmq-server@98b1daf

GHSA-pj24-8j6m-vq9q is a Information Exposure vulnerability. A fix is available — see the affected versions and patch details below.

Published
Updated
Affected
1 product
Patched
See advisory
Exploits
None indexed
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-pj24-8j6m-vq9q.

EPSS Exploitation Probability

via FIRST.org ↗
2.8%probability of exploitation in next 30 days
Lower Risk+0.85%
Lower risk than most CVEs86th percentile — riskier than 86% of all scored CVEsHighest risk
1.49%2.10%2.72%3.34%2.0%2.8%Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

Description

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

Affected Products

1 product · 1 configurations
Application
rabbitmq serverbroadcom
≥ 3.13.0 && < 4.2.6
range

Detection & mitigation playbook

Vulnerability
  1. Detect

    Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).

  2. Fix

    Upgrade the affected component to the fixed release for GHSA-pj24-8j6m-vq9q, or apply your distribution's backported patch — distro builds are often patched at an older version number, so check your vendor's advisory rather than the upstream version alone.

  3. Workarounds

    Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.

How to detect GHSA-pj24-8j6m-vq9q

A community-maintained Nuclei template exists for this CVE. You can scan for it directly:

nuclei -id ghsa-pj24-8j6m-vq9q -u https://target
Template
RabbitMQ Management - OAuth 2 Client Secret Disclosure
Severity
high
Impact
Unauthenticated attackers can access OAuth 2 client secrets, leading to credential exposure and potential unauthorized access.
Remediation
Update to versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 or later.

Template by ProjectDiscovery nuclei-templates (aryu-ru), MIT licensed. View the full template. Scan only systems you are authorised to test.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant
ProductFixed inAdvisory
Red Hat Hardened Imagesrabbitmq-server4-3-main-4.3.2-1.hum1RHSA-2026:35939
Red Hat Hardened Imagesrabbitmq-server4-2-main-4.2.8-1.hum1RHSA-2026:35940

Frequently Asked Questions

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
O3 Security · Impact-Aware SCA

Is GHSA-pj24-8j6m-vq9q in your dependencies?

Find it across , including transitive dependencies.

RabbitMQ: Unauthenticated disclosure of OAuth client…