PT-2026-98910 · Vmware · Rabbitmq
CVE-2026-67234
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
2.3
Low
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.7
RabbitMQ versions 4.3.0 through 4.3.1
Description
The
get auth mechanism/1 function uses term to binary/1 on the strict auth mechanism or preferred auth mechanism atom when clearing cookies. This process generates a non-ASCII cookie name that violates RFC 6265, which may prevent the browser from deleting the preference. This results in stale authentication-mechanism preferences persisting across logout and login cycles.Recommendations
Update to version 4.2.8.
Update to version 4.3.2.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq