CVE-2026-57216

Description

A flaw was found in RabbitMQ, a messaging and streaming broker. The AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication mechanisms incorrectly perform a loopback check. This allows a user, typically restricted to loopback connections (such as a guest user), to connect remotely. This occurs when traffic is routed through a trusted PROXY-protocol path and the backend listener is bound to the loopback interface, as the check uses the listener-side socket address instead of the actual client source address.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score6.3106.8
Attack VectorNetworkNetworkNetwork
Attack ComplexityHighLowHigh
Privileges RequiredLowNoneNone
User InteractionNoneNoneNone
ScopeChangedChangedChanged
ConfidentialityHighHighHigh
Integrity ImpactNoneHighNone
Availability ImpactNoneHighNone

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

NVD: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

Understanding the Weakness (CWE)

Access Control

Technical Impact: Bypass Protection Mechanism

Frequently Asked Questions

Want to get errata notifications? Sign up here.