PT-2026-98914 · Vmware · Rabbitmq
CVE-2026-67242
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 4.2.0 through 4.2.8
RabbitMQ versions 4.3.0 through 4.3.2
Description
An issue exists in the OAuth2 implementation where token expiry checks are skipped if the Identity Provider (IdP) emits the
exp claim as a JSON float. This occurs because the validatetokenexpiry/1 and expirytimestamp/1 functions use a guard that only processes integer values, causing float values to be ignored. Consequently, the login-time expiry check and the mid-connection disconnect timer are bypassed, allowing previously valid but expired signed tokens to be accepted and preventing connections from timing out.Recommendations
Update to version 4.2.9.
Update to version 4.3.3.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq