{"id":"CVE-2026-57219","title":"RabbitMQ is a messaging and streaming broker","summary":"RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secre…","severity":"none","cwe":["CWE-200"],"published":"2026-07-10","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57219","references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/commit/aa387c4451e7b674df3e3ba89df86a99d697cc7f","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/16083","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/pull/16086","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","label":"security-advisories@github.com"},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-pj24-8j6m-vq9q","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.01988,"epssPercentile":0.79754,"ingestedAt":"2026-07-11T20:15:27.317Z","exploits":{"nuclei":["CVE-2026-57219"],"checkedAt":"2026-09-24T07:53:09.221Z"},"exploitAvailable":true,"slug":"CVE-2026-57219","body":"## Overview\n\nRabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":15,"depthScoreParts":{"impact":2.8,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":5370,"id":"CVE-2026-57219","ts":1788887272855,"field":"exploit_available","old":"false","new":"true"},{"seq":4253,"id":"CVE-2026-57219","ts":1788886387763,"field":"exploit_available","old":"true","new":"false"},{"seq":3003,"id":"CVE-2026-57219","ts":1788883051071,"field":"exploit_available","old":"false","new":"true"},{"seq":2032,"id":"CVE-2026-57219","ts":1788882455712,"field":"exploit_available","old":"true","new":"false"},{"seq":1106,"id":"CVE-2026-57219","ts":1788881892891,"field":"exploit_available","old":"false","new":"true"}]}