CVE-2026-57216: RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Other sources
RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.13.7-7 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 3.13.15 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 4.0.20 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 4.1.11 - Upgrade
Upgrade
RabbitMQto a version that resolves this vulnerability.Fixed in 4.2.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57216?
CVE-2026-57216 is classified as critical with a severity score of 10.
How do I fix CVE-2026-57216?
To fix CVE-2026-57216, upgrade RabbitMQ to versions 3.13.15, 4.0.20, 4.1.11, or 4.2.6 or later.
What types of protocols are affected by CVE-2026-57216?
CVE-2026-57216 affects AMQP 0-9-1, AMQP 1.0, and Stream Protocol.
What can be exploited in CVE-2026-57216?
CVE-2026-57216 can be exploited to allow loopback-restricted users, such as guest, to connect remotely under certain conditions.
Which software versions are vulnerable to CVE-2026-57216?
RabbitMQ versions prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6 are vulnerable to CVE-2026-57216.