Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-57211: RabbitMQ on Windows exposes users to malicious UNC paths
CVE-2026-57211
CVE-2026-57211
Summary
A bug in the RabbitMQ management plugin on Windows versions prior to 4.1.11 and 4.2.6 can allow an attacker to trick the system into accessing malicious shared files. This could lead to unauthorized access to your network. Update to RabbitMQ version 4.1.11 or 4.2.6 to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rabbitmq | rabbitmq-server | >= 4.2.0, < 4.2.6 |
| broadcom | rabbitmq_server |
>= 4.1.0, < 4.2.6 cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:* |
Original title
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_...
Original description
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.
mitre CVSS3.1
6.5
Vulnerability type
CWE-36
CWE-918
Server-Side Request Forgery (SSRF)
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-7v84-m3g5-v... x_refsource_CONFIRM
- https://github.com/rabbitmq/rabbitmq-server/pull/15803 x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/commit/39c3a8e9c71da0403d8dfc13f700e... x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/commit/6730797f6a34b4e8308cea60adf12... x_refsource_MISC
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 x_refsource_MISC
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026