bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: CVE-2026-9133

show all
Thursday, August 20, 2026

CVE-2026-9133: Critical Arbitrary File Read in rabbitmq-aws Plugin

The rabbitmq-aws plugin (versions 0.1.0–0.2.0) has a nasty security hole: debug code slipped into production that lets authenticated users read any file the RabbitMQ process can access. The vulnerability lives in the PUT /api/aws/arn/validate endpoint, which accepts a debug ARN scheme (arn:aws-debug:file) with no kill switch. If you're running affected versions, update immediately—this one requires your action.

source: [aws/security-bulletin]