---
id: CVE-2026-57218
title: RabbitMQ is a messaging and streaming broker
summary: >-
  RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP
  0-9-1 allows an existing consumer to keep receiving messages after OAuth token
  expiry or connection.update_secret refresh to reduced scopes because existing
  cons…
severity: none
cwe:
  - CWE-863
published: '2026-07-10'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57218'
references:
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/commit/501ad947cd6bbcc9486fe96e0d073992bfe52cc4
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/commit/db20d6c0fcf3056030f244b5adab0d45c0db0c9e
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/pull/16092'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/pull/16097'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00565
epssPercentile: 0.4461
ingestedAt: '2026-07-11T20:15:27.302Z'
---

## Overview

RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
