{"id":"CVE-2026-57215","title":"RabbitMQ is a messaging and streaming broker","summary":"RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route t…","severity":"none","cwe":["CWE-863"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57215","references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/9055500d10ca7629dd2b051c6dc7a4b0bb8f6734","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/c84f3c880e0f22b49c01237cf8f86e176eeadc72","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/15935","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/15938","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-5cq3-v9jx-p3x3","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00652,"epssPercentile":0.49849,"ingestedAt":"2026-07-11T20:15:27.074Z","slug":"CVE-2026-57215","body":"## Overview\n\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}