PT-2026-42261 · Amazon · Rabbitmq Aws
The-Mikedavis
·
Published
2026-05-20
·
Updated
2026-05-29
·
CVE-2026-9133
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
amazon-mq rabbitmq-aws versions prior to 0.2.1
Description
Active debug code in the ARN resolver allows remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. This occurs because the 'PUT /api/aws/arn/validate' endpoint accepts a debug ARN scheme (
arn:aws-debug:file).Recommendations
Upgrade to version 0.2.1.
Rotate any associated private certificate keys if RabbitMQ is configured to use TLS for connections.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq Aws