Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-57215

RabbitMQ direct reply-to bindings persist after unbind and allow reply-channel injection

Technology

RabbitMQ

CVSS Score

8.8 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

July 10, 2026

OSSeva Coverage

Fixed upstream

Description

Volatile direct reply-to queues could be accepted as binding destinations at bind and route time but were missing from the Khepri-backed deletion checks, so foreign bindings to amq.rabbitmq.reply-to destinations left persistent route entries after unbind. Another client could use them to inject messages into a reply channel. Fixed in 4.2.6 and in the commercial 3.13.15, 4.0.20 and 4.1.11.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.