Vulnerability in RabbitMQ Messaging Broker Affects Multiple Versions
CVE-2026-67411
6MEDIUM
What is CVE-2026-67411?
A vulnerability in RabbitMQ allows an attacker to bypass the source-address restrictions on MQTT authentication when using a trusted PROXY Protocol frontend. This issue arises in versions from 3.13.0 to 3.13.18, and several other specific releases. If an attacker is able to reach the trusted frontend and possesses valid credentials for an account restricted through loopback, they may exploit this vulnerability. Importantly, this flaw does not compromise password authentication. Fixed versions have been released to address the issue.
Affected Version(s)
rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3
rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9
rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14
