Server-Side Request Forgery (SSRF) in RabbitMQ - #VU134801
Published: June 18, 2026
RabbitMQ
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery (ssrf) in rabbitmq management plugin static file handler (rabbit_mgmt_wm_static) when handling a crafted request path containing url-encoded unc path segments on windows. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation requires Windows and two or more management extension plugins to be enabled. On domain-joined systems, the issue can coerce outbound SMB authentication and expose the machine account NTLMv2 hash.