PT-2026-42261 · Amazon · Rabbitmq Aws

The-Mikedavis

·

Published

2026-05-20

·

Updated

2026-05-29

·

CVE-2026-9133

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions amazon-mq rabbitmq-aws versions prior to 0.2.1
Description Active debug code in the ARN resolver allows remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. This occurs because the 'PUT /api/aws/arn/validate' endpoint accepts a debug ARN scheme (arn:aws-debug:file).
Recommendations Upgrade to version 0.2.1. Rotate any associated private certificate keys if RabbitMQ is configured to use TLS for connections.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-9133

Affected Products

Rabbitmq Aws