Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2026-67404: RabbitMQ server can accept forged tokens when TLS not verified
CVE-2026-67404 · published 16 days ago
Summary
RabbitMQ versions before 3.13.15, 4.0.20, 4.1.11, 4.2.6 and 4.3.0 may skip checking the security certificate if none is provided, without warning. This lets an attacker who can see or alter network traffic feed a fake key list, causing the broker to trust any token it receives. Update RabbitMQ to the listed versions or configure a valid certificate authority file to stop the fallback.
What to do
- Update debian rabbitmq-server to version 4.3.0-2.
- Update rabbitmq to version 4.2.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | rabbitmq-server | >= 3.13.0, < 3.13.15 |
| Ubuntu:Pro:16.04:LTS | canonical | rabbitmq-server | All versions |
| Debian:12 | debian | rabbitmq-server | All versions |
| Debian:14 | debian | rabbitmq-server |
< 4.3.0-2 Fix: upgrade to 4.3.0-2
|
| Bitnami | – | rabbitmq |
>= 4.2.0, < 4.2.6 Fix: upgrade to 4.2.6
|
Original advisory text
RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-middle position can forge the JWKS response, which leads the broker to accept arbitrary JWTs. Preconditions include The OAuth2 plugin must be in use with no cacertfile configured and the OS CA bundle empty or unreadable (for example, in a minimal container), and the attacker must hold a network man-in-the-middle position.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
References
- https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-37wx-r6q9-6...
- https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6
- https://ubuntu.com/security/CVE-2026-67404 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-67404 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-67404 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67404... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-67404 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.2
Critical
Type
CWE-295Improper Certificate Validation
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-67404 · NVD
CVE-2026-67404 · MITRE
UBUNTU-CVE-2026-67404 · OSV
DEBIAN-CVE-2026-67404 · OSV
CVE-2026-67404 · OSV
GHSA-37wx-r6q9-6fhj · GHSA
BIT-rabbitmq-2026-67404 · OSV
Track software like this
Free during beta