PT-2026-97583 · Rabbitmq+1 · Rabbitmq Trust Store+1

CVE-2026-67231

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions RabbitMQ versions prior to 3.13.15 RabbitMQ versions prior to 4.0.20 RabbitMQ versions prior to 4.1.11 RabbitMQ versions prior to 4.2.6 RabbitMQ versions prior to 4.3.0
Description An issue exists in the trust-store plugin where the verify fun function overrides certificate validation errors when a presented certificate matches a whitelisted one. The matching process relies on the extract issuer id/1 function, which uses public key:pkix issuer id/2 to extract the IssuerName and SerialNumber directly from the certificate body. Because these fields are taken verbatim and are not verified against public-key material, signatures, or fingerprints, and the stored DER is not compared against the presented certificate, a TLS client-authentication bypass is possible. An attacker who knows or can guess the issuer DN and serial number of a whitelisted certificate can connect using a forged self-signed certificate. This requires the rabbitmq trust store plugin to be enabled and configured as the TLS verify fun.
Recommendations Update to version 3.13.15. Update to version 4.0.20. Update to version 4.1.11. Update to version 4.2.6. Update to version 4.3.0. As a temporary mitigation, disable the rabbitmq trust store plugin if it is being used as the TLS verify fun.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67231
GHSA-CW8C-4M83-9C6W

Affected Products

Rabbitmq
Rabbitmq Trust Store