PT-2026-105052 · Azure Linux · Rabbitmq-Server

Published

2026-09-23

·

Updated

2026-09-23

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq web mqtt/src/rabbit web mqtt handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq web stomp/src/rabbit web stomp handler.erl:102) validates the Origin header on the WebSocket upgrade. Under ssl cert login=true, the browser presents the client certificate automatically, so an attacker's JavaScript running in the victim's browser can authenticate as the victim. Preconditions include The non-default configuration use http auth=true (Web-STOMP) or ssl cert login=true (both plugins) must be enabled. The issue is harmless under the default in-band CONNECT credential configuration.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-105747

Affected Products

Rabbitmq-Server