<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rabbitmq on CuraSec</title><link>https://curasec.metacog.co.kr/tags/rabbitmq/</link><description>Recent content in Rabbitmq on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 15 Jul 2026 12:11:39 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/rabbitmq/index.xml" rel="self" type="application/rss+xml"/><item><title>RabbitMQ Flaws Could Leak OAuth Secrets, Break Tenant Isolation</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> RabbitMQ is widely deployed as enterprise messaging infrastructure; these access control flaws — OAuth client secret leakage and cross-tenant queue metadata exposure — represent real risk for teams running it in multi-tenant or OAuth-integrated configurations. No active exploitation or PoC reported, but identify affected versions and schedule patching once a fix is available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no reported exploitation, and no actionable detection surface in this disclosure; file for context in case RabbitMQ compromise indicators surface later, but no hunt or detection work is warranted now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>