Arbitrary file read in rabbitmq-aws plugin
Published May 20, 2026
8.3
HIGHCVSS 4.0
EPSS 1.08%
Description
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process.
To remediate this issue, customers should upgrade to version 0.2.1 of rabbitmq-aws. If RabbitMQ is configured to use TLS for connections, we also recommend rotating any associated private certificate keys.
Affected products
-
- Version 0.1.0StatusaffectedConstraints<=0.2.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| AWS | RabbitMQ AWS | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://aws.amazon.com/security/security-bulletins/2026-034-aws/ vendor-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31181 Advisory
- https://github.com/amazon-mq/rabbitmq-aws/releases/tag/0.2.1 patch
- https://github.com/amazon-mq/rabbitmq-aws/security/advisories/GHSA-8554-wg4r-7hxm third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-034-aws/ | vendor-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31181 | Advisory | |
| https://github.com/amazon-mq/rabbitmq-aws/releases/tag/0.2.1 | patch | |
| https://github.com/amazon-mq/rabbitmq-aws/security/advisories/GHSA-8554-wg4r-7hxm | third-party-advisory |
Change history (0)
No recorded changes yet.