Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-67231: RabbitMQ may accept fake client certificates
CVE-2026-67231 · published 16 days ago
Summary
RabbitMQ servers that run the trust‑store plug‑in on older versions can be tricked into trusting a fabricated certificate if an attacker knows the issuer name and serial number of a approved certificate. This lets an unauthorized user connect as a trusted client. Upgrade to the latest RabbitMQ release or disable the vulnerable plug‑in to close the gap.
What to do
- Update debian rabbitmq-server to version 4.3.0-2.
- Update rabbitmq to version 4.2.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.15 |
| Ubuntu:Pro:16.04:LTS | canonical | rabbitmq-server | All versions |
| Debian:12 | debian | rabbitmq-server | All versions |
| Debian:14 | debian | rabbitmq-server |
< 4.3.0-2 Fix: upgrade to 4.3.0-2
|
| Bitnami | – | rabbitmq |
>= 4.2.0, < 4.2.6 Fix: upgrade to 4.2.6
|
Original advisory text
RabbitMQ: Trust-store whitelist by Issuer+Serial only
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun Attacker knows or can guess the {Issuer, Serial} of at least one whitelisted cert (non-secret; exposed via CLI/logs/any cert copy). This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
References
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6 Third Party Advisory
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.0 Third Party Advisory
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-cw8c-4m83-9... Third Party Advisory
- https://ubuntu.com/security/CVE-2026-67231 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-67231 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67231... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-67231 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-67231 Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Type
CWE-295Improper Certificate Validation
Timeline
Published23 Sep 2026
Updated7 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-67231 · NVD
CVE-2026-67231 · MITRE
UBUNTU-CVE-2026-67231 · OSV
DEBIAN-CVE-2026-67231 · OSV
CVE-2026-67231 · OSV
GHSA-cw8c-4m83-9c6w · GHSA
BIT-rabbitmq-2026-67231 · OSV
Track software like this
Free during beta