Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

CVE-2026-67237: RabbitMQ lets attacker run script through OAuth token

CVE-2026-67237 · published 3 days ago
Summary

Versions of RabbitMQ server 4.2.0‑4.2.7 and 4.3.0‑4.3.1 can insert an attacker‑controlled token into a JavaScript file that is shown in the management console. This could let a malicious user run code in the browser of anyone viewing the console, potentially stealing data or changing settings. Upgrade to RabbitMQ 4.2.8 or later (or 4.3.2 or later) to stop the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– rabbitmq rabbitmq-server >= 4.2.0, < 4.2.8
Debian:14 debian rabbitmq-server All versions
Original advisory text
RabbitMQ: Reflected XSS via the OAuth bootstrap JS endpoint
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping, allowing attacker-controlled token content to execute JavaScript in the management UI origin. The endpoint is exposed before authentication only when management.oauth_enabled is true, and exploitation through the cookie path additionally requires the attacker to plant an access_token cookie on the management host. This issue is fixed in versions 4.2.8 and 4.3.2.
Severity
7.5 High
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published25 Sep 2026
Updated28 Sep 2026
First seen25 Sep 2026
Track software like this
Free during beta