CVE-2026-57211: RabbitMQ: UNC SSRF affecting the management UI on Windows
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbitmgmtwmstatic can pass URL-encoded backslashes to erlprimloader:readfileinfo before path validation when multiple management extension plugins are enabled, causing outbound DNS and SMB requests to attacker-controlled UNC paths. This issue is fixed in versions 4.1.11 and 4.2.6.
Other sources
RabbitMQ: UNC SSRF affecting the management UI on Windows
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.7-7 - Upgrade
Upgrade
RabbitMQ (management plugin)to a version that resolves this vulnerability.Fixed in 4.1.11 - Upgrade
Upgrade
RabbitMQ (management plugin)to a version that resolves this vulnerability.Fixed in 4.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57211?
CVE-2026-57211 has a medium severity level rated at 6.5.
How do I fix CVE-2026-57211?
To fix CVE-2026-57211, upgrade RabbitMQ to versions 4.1.11 or 4.2.6 or later on Windows.
What type of vulnerability is CVE-2026-57211?
CVE-2026-57211 is a Server-Side Request Forgery (SSRF) vulnerability.
What impact does CVE-2026-57211 have on RabbitMQ?
CVE-2026-57211 can allow an attacker to exploit the management UI on Windows due to improper path validation.
Which component of RabbitMQ is affected by CVE-2026-57211?
CVE-2026-57211 affects the RabbitMQ management plugin static file handler.