PT-2026-42261 · Amazon · Rabbitmq Aws

·

CVE-2026-9133

·

Published

2026-05-20

·

Updated

2026-05-29

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions amazon-mq rabbitmq-aws versions prior to 0.2.1
Description Active debug code in the ARN resolver allows remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. This occurs because the 'PUT /api/aws/arn/validate' endpoint accepts a debug ARN scheme (arn:aws-debug:file).
Recommendations Upgrade to version 0.2.1. Rotate any associated private certificate keys if RabbitMQ is configured to use TLS for connections.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9133
GHSA-8554-WG4R-7HXM

Affected Products

Rabbitmq Aws