hacker-news · Crawled Jul 14, 2026
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
2 CVEs
Read original article ↗
AI Summary
Two critical vulnerabilities in RabbitMQ, CVE-2026-57219 and CVE-2026-57221, could allow unauthenticated attackers to leak OAuth client secrets and enable authenticated users to bypass tenant boundaries by accessing cross-tenant queue metadata. The flaws, present since early 2024, affect RabbitMQ versions 3.13.0 and later and have been patched in recent releases. CVE-2026-57219 exposes a misconfigured HTTP API endpoint that leaks sensitive OAuth secrets, posing high risk in cloud or multi-tenant environments with exposed management interfaces.
AI-extracted · verify before operational use