Skip to content
AWSAWS-2026-034

Arbitrary file read in rabbitmq-aws plugin

UnratedCVE-2026-9133 · Published May 20, 2026 · updated Sep 22, 2026

Bulletin ID: 2026-034-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/20/2026 12:45 PM PDT   Description: rabbitmq-aws is a RabbitMQ plugin that resolves AWS ARNs in broker configuration at startup, fetching secrets (e.g., TLS certificates, private keys, passwords) from AWS services (Secrets Manager, S3, ACM Private CA) and passing them in-memory to RabbitMQ. We identified CVE-2026-9133 , an active debug code issue in the plugin's ARN resolver. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. The debug code was inadvertently shipped in production builds with no mechanism to disable it. Impacted versions:  >=0.1.0, Resolution: This issue has been addressed in rabbitmq-aws version 0.2.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. We also recommend rotating any secrets stored in files to which the RabbitMQ process had read access. Workarounds: The plugin can be disabled with rab...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID: 2026-034-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/20/2026 12:45 PM PDT   Description: rabbitmq-aws is a RabbitMQ plugin that resolves AWS ARNs in broker configuration at startup, fetching secrets (e.g., TLS certificates, private keys, passwords) from AWS services (Secrets Manager, S3, ACM Private CA) and passing them in-memory to RabbitMQ. We identified CVE-2026-9133 , an active debug code issue in the plugin's ARN resolver. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. The debug code was inadvertently shipped in production builds with no mechanism to disable it. Impacted versions:  >=0.1.0, Resolution: This issue has been addressed in rabbitmq-aws version 0.2.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. We also recommend rotating any secrets stored in files to which the RabbitMQ process had read access. Workarounds: The plugin can be disabled with rabbitmq-plugins disable aws. This removes the validation endpoint so that any further PUT requests return 405 (Method Not Allowed) and the requested ARNs are not fetched. Note that disabling the plugin also removes ARN resolution at startup, meaning the broker will need to fall back to filesystem-based certificate configuration. References: CVE-2026-9133 GHSA-8554-wg4r-7hxm Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-034-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-9133 - Arbitrary file read in rabbitmq-aws plugin Bulletin ID: 2026-034-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 05/20/2026 12:45 PM PDT   Description: rabbitmq-aws is a RabbitMQ plugin that resolves AWS ARNs in broker configuration at startup, fetching secrets (e.g., TLS certificates, private keys, passwords) from AWS services (Secrets Manager, S3, ACM Private CA) and passing them in-memory to RabbitMQ. We identified CVE-2026-9133 , an active debug code issue in the plugin's ARN resolver. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint might allow remote authenticated users to perform arbitrary file reads on any file accessible to the RabbitMQ process. The debug code was inadvertently shipped in production builds with no mechanism to disable it. Impacted versions:  >=0.1.0, Resolution: This issue has been addressed in rabbitmq-aws version 0.2.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. We also recommend rotating any secrets stored in files to which the RabbitMQ process had read access. Workarounds: The plugin can be disabled with rabbitmq-plugins disable aws. This removes the validation endpoint so that any further PUT requests return 405 (Method Not Allowed) and the requested ARNs are not fetched. Note that disa

Severity from
no source yet

More AWS advisories

All AWS
Advisory
Tool Execution Without Authorization via Piped Stdin in Kiro CLI
UnratedMay 22
Remote Code Execution in amazon-redshift-python-driver
UnratedMay 18
Missing integrity verification in Triton inference handler in Amazon SageMaker Python SDK
Medium6.4May 14
Issue with Amazon SageMaker Python SDK - Model artifact integrity verification issues...
UnratedMay 14
Heap out-of-bounds read in coreMQTT MQTT5 property parsing
UnratedMay 14
Ongoing updates on Copy.fail and variants
UnratedMay 13

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.