Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-57216: RabbitMQ: Guest User Can Connect Remotely Through Proxy

CVE-2026-57216 CVE-2026-57216
Summary

A security issue in older RabbitMQ versions allowed a guest user to connect from outside the local network through a proxy. This could be a risk if your RabbitMQ server is exposed to the internet. To fix this, update to RabbitMQ versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rabbitmq rabbitmq-server >= 4.2.0, < 4.2.6
broadcom rabbitmq_server >= 3.13.0, < 4.2.6
cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*
Original title
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as gues...
Original description
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
mitre CVSS3.1 6.8
Vulnerability type
CWE-287 Improper Authentication
Published: 10 Jul 2026 · Updated: 20 Jul 2026 · First seen: 10 Jul 2026