WebSocket Vulnerability in RabbitMQ Messaging Broker
CVE-2026-67405

5.3MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-67405?

RabbitMQ is susceptible to a WebSocket vulnerability that bypasses Origin header validation in its Web-MQTT and Web-STOMP handlers. When enabled with specific configurations (ssl_cert_login=true or use_http_auth=true), an attacker can remotely authenticate as an unintended user by exploiting clients' certificates automatically sent by web browsers. This issue significantly compromises the security of affected deployments, necessitating immediate updates to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, or 4.3.0 to mitigate risks.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.