CVE-2026-66077
Stored XSS in the RabbitMQ management UI connection page through a TLS client certificate subject
Technology
RabbitMQ
CVSS Score
7.3 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
The management UI renders a connection's peer certificate subject and issuer without HTML escaping, and its content security policy allows inline script. With verify_peer enabled, anyone who can get a client certificate from a CA the broker trusts, for example through self-service corporate PKI, can put script in the subject. It runs when an administrator views the connection and can lead to account takeover.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.