PT-2026-44002 · Rabbitmq · Rabbitmq
Retpoline
·
Published
2026-05-27
·
Updated
2026-06-04
·
CVE-2026-44838
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.3
Description
The MQTT plugin in RabbitMQ allows topic-level authorization using regular expressions with variable substitution. When administrators use patterns like ^{client id}-sensors$ to restrict access, the
client id provided by the user in the MQTT CONNECT packet is inserted into the regex pattern without escaping special characters. This allows an authenticated MQTT user to inject regex operators and bypass authorization.Recommendations
Update to version 4.2.4 or 4.3.0.
Fix
DoS
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq