CVE-2026-25768
LavinMQ is a high-performance message queue & streaming server. Before 2.6.6, an authenticated user could access metadata in the broker they should not have access to. This vulnerability is fixed in 2.6.6.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25768.json, https://github.com/cloudamqp/lavinmq/commit/e871f8d0a53685f04e39e6410a2421c1f82803b0, https://github.com/cloudamqp/lavinmq/pull/1669, https://github.com/cloudamqp/lavinmq/security/advisories/GHSA-r2mh-8vq6-qf7m, https://nvd.nist.gov/vuln/detail/CVE-2026-25768
