AMQP Authorization Error in RabbitMQ Management UI
CVE-2026-67421
What is CVE-2026-67421?
In RabbitMQ versions from 3.13.0 to 3.13.19, as well as several versions of 4.0, 4.1, 4.2, and 4.3, a vulnerability exists within the RabbitMQ Management UI that can expose sensitive information. If the OAuth management interface is enabled, an attacker can potentially manipulate the management UI to render an authorization error that includes a queue name controlled by the attacker. This can occur when a management administrator views messages from a queue for which they lack read permissions. The compromised Content Security Policy may allow the attacker to target a victim's Authorization header when the administrator interacts with a specially crafted message, particularly through a relative refresh that neglects to define base-uri and connect-src directives. This vulnerability is addressed in the fixed versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5.
Affected Version(s)
rabbitmq-server >= 3.13.0, < 3.13.19 < 3.13.0, 3.13.19
rabbitmq-server >= 4.0.0, < 4.0.24 < 4.0.0, 4.0.24
rabbitmq-server >= 4.1.0, < 4.1.15 < 4.1.0, 4.1.15
