hacker-news · Crawled Jul 14, 2026

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

2 CVEs
Read original article ↗

AI Summary

Two critical vulnerabilities in RabbitMQ, CVE-2026-57219 and CVE-2026-57221, could allow unauthenticated attackers to leak OAuth client secrets and enable authenticated users to bypass tenant boundaries by accessing cross-tenant queue metadata. The flaws, present since early 2024, affect RabbitMQ versions 3.13.0 and later and have been patched in recent releases. CVE-2026-57219 exposes a misconfigured HTTP API endpoint that leaks sensitive OAuth secrets, posing high risk in cloud or multi-tenant environments with exposed management interfaces.

AI-extracted · verify before operational use

Extracted Entities 2 found

MITRE ATT&CK TTPs 5 techniques