Skip to content

Known CVE

RabbitMQ Management - OAuth 2 Client Secret Disclosure

RabbitMQ < 3.13.15, 4.0.20, 4.1.11, and 4.2.6 contains an information disclosure caused by the obsolete GET /api/auth endpoint exposing OAuth 2 client secrets when management.oauth_client_secret is configured, letting unauthenticated attackers access sensitive credentials, exploit requires management plugin and OAuth configuration enabled.

CVE-2026-57219

High2026CVSS 7.5CWE-522

cve2026 · rabbitmq · broadcom · oauth · exposure · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website