Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-57216

44
FAUCET Score

RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.

First published: Jul 10, 2026Last modified: Jul 10, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.13.0, < 4.2.6CPE matchmatch criteria
cpe:2.3:a:broadcom:rabbitmq_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.50%
Probability of exploitation in next 30 days
EPSS Percentile
40.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0050 is in the 19th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0Fixed in: 3.13.7-7

Vendor Advisories (1)

microsoft2026-Jul/CVE-2026-57216Moderate

RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks

Jul 14, 2026

References

github.com / rabbitmq/rabbitmq-server/commit/7273c9eb6920abcde17b892dbe97ccaf906ead47
Patch
github.com / rabbitmq/rabbitmq-server/commit/9f8c39fcf0acbc43080ee7017a62a02832114112
Patch
github.com / rabbitmq/rabbitmq-server/pull/15936
Issue TrackingPatch
github.com / rabbitmq/rabbitmq-server/pull/15940
Issue TrackingPatch
github.com / rabbitmq/rabbitmq-server/releases/tag/v4.2.6
Release Notes
github.com / rabbitmq/rabbitmq-server/security/advisories/GHSA-36m6-588r-vqcw
ExploitVendor Advisory