CVE-2026-9133

7.7

Amazon · RabbitMQ AWS

Active debug code in the Amazon RabbitMQ AWS ARN resolver may allow authenticated attackers to access sensitive information.

Executive summary

The presence of active debug code in Amazon RabbitMQ AWS versions 0.1.0 through 0.2.0 poses a significant risk of unauthorized information disclosure.

Vulnerability

This vulnerability involves the inclusion of active debug code within the ARN resolver component (CWE-489). The attack vector requires a low-privilege authenticated user to successfully trigger the flaw.

Business impact

The exposure of debug functionality can lead to the unauthorized disclosure of sensitive system information, potentially aiding in further exploitation of the environment. With a CVSS score of 7.7, this is a High-severity vulnerability that warrants prompt attention to prevent potential lateral movement or data leakage within the messaging infrastructure.

Remediation

Immediate Action: Update the Amazon RabbitMQ AWS package to version 0.2.1 or later as provided in the vendor release notes.

Proactive Monitoring: Review system and application access logs for unusual activity related to the ARN resolver or unexpected calls to debugging endpoints.

Compensating Controls: If an immediate update is not feasible, restrict access to the affected service to only trusted, essential users and apply network-level segmentation to minimize exposure.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the High severity of this information disclosure vulnerability, organizations should prioritize upgrading to version 0.2.1. Removing the residual debug code is essential to maintaining the security posture of your messaging services and preventing potential unauthorized data access.

More Amazon CVEs