PT-2026-97587 · Vmware · Rabbitmq
CVE-2026-67405
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions prior to 3.13.15
RabbitMQ versions prior to 4.0.20
RabbitMQ versions prior to 4.1.11
RabbitMQ versions prior to 4.2.6
RabbitMQ versions prior to 4.3.0
Description
The Web-MQTT handler and the Web-STOMP handler do not validate the Origin header during the WebSocket upgrade process. When the
ssl cert login configuration is enabled, browsers automatically present the client certificate, allowing malicious JavaScript executing in a victim's browser to authenticate as that user. This issue requires specific non-default configurations to be active: use http auth for Web-STOMP or ssl cert login for both plugins. The issue does not affect the default in-band CONNECT credential configuration.Recommendations
Update to version 3.13.15
Update to version 4.0.20
Update to version 4.1.11
Update to version 4.2.6
Update to version 4.3.0
Disable the
ssl cert login configuration to prevent automatic client certificate presentation.
Disable the use http auth configuration for Web-STOMP.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq