Information disclosure in RabbitMQ Server - #VU150999
Published: September 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose virtual-host existence.
The vulnerability exists due to improper access control in the Stream consumer management endpoint when handling GET requests for a virtual host. A remote user can submit a request containing a target virtual-host name to disclose virtual-host existence.
Exploitation requires the Management, Stream, and Stream Management plugins to be enabled.