PT-2026-98918 · Vmware · Rabbitmq

CVE-2026-67409

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ versions 3.13.0 through 3.13.17 RabbitMQ versions 4.0.0 through 4.0.22 RabbitMQ versions 4.1.0 through 4.1.13 RabbitMQ versions 4.2.0 through 4.2.8 RabbitMQ versions 4.3.0 through 4.3.2
Description The JWKS key fetching mechanism in uaajwt.erl fails to validate the HTTP response status code when downloading signing keys from the OAuth2 provider's JWKS endpoint. Consequently, non-200 responses, such as 4xx and 5xx errors, are treated as successful. If the endpoint returns an error response containing a valid JSON body that lacks a keys field, all previously cached signing keys are destroyed. This leads to a persistent authentication denial of service where all OAuth2/JWT authentication fails for all users until a successful JWKS refresh occurs, allowing a single attacker to deny access to all legitimate OAuth2 users.
Recommendations Update RabbitMQ to version 3.13.18. Update RabbitMQ to version 4.0.23. Update RabbitMQ to version 4.1.14. Update RabbitMQ to version 4.2.9. Update RabbitMQ to version 4.3.3.

Exploit

Fix

DoS

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67409
GHSA-QW3H-QQM9-JRW8

Affected Products

Rabbitmq