Missing Authorization in RabbitMQ Server - CVE-2026-61837
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to missing authorization in the AMQP 1.0 HTTP-over-AMQP management endpoint GET /bindings when handling management requests over an AMQP 1.0 management link pair. A remote user can send a specially crafted GET /bindings request to disclose sensitive information.
The issue exposes binding topology within the virtual host, including source and destination names, routing keys, binding arguments, and binding location URIs.