Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-67231

RabbitMQ trust store plugin accepts forged client certificates that match a whitelisted issuer and serial

Technology

RabbitMQ

CVSS Score

9.1 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

The rabbitmq_trust_store plugin installs a verify_fun that overrides unknown_ca and selfsigned_peer errors when the presented certificate matches a whitelisted one. The match uses only the issuer name and serial number read from the presented certificate, with no key, fingerprint or signature check. An attacker who knows the issuer and serial of any whitelisted certificate, which are not secret, can pass TLS client authentication with a forged self-signed certificate. Precondition: the trust store plugin enabled and used for peer verification.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.