PT-2026-98918 · Vmware · Rabbitmq
CVE-2026-67409
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ versions 3.13.0 through 3.13.17
RabbitMQ versions 4.0.0 through 4.0.22
RabbitMQ versions 4.1.0 through 4.1.13
RabbitMQ versions 4.2.0 through 4.2.8
RabbitMQ versions 4.3.0 through 4.3.2
Description
The JWKS key fetching mechanism in
uaajwt.erl fails to validate the HTTP response status code when downloading signing keys from the OAuth2 provider's JWKS endpoint. Consequently, non-200 responses, such as 4xx and 5xx errors, are treated as successful. If the endpoint returns an error response containing a valid JSON body that lacks a keys field, all previously cached signing keys are destroyed. This leads to a persistent authentication denial of service where all OAuth2/JWT authentication fails for all users until a successful JWKS refresh occurs, allowing a single attacker to deny access to all legitimate OAuth2 users.Recommendations
Update RabbitMQ to version 3.13.18.
Update RabbitMQ to version 4.0.23.
Update RabbitMQ to version 4.1.14.
Update RabbitMQ to version 4.2.9.
Update RabbitMQ to version 4.3.3.
Exploit
Fix
DoS
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq