CVE-2026-67231
RabbitMQ trust store plugin accepts forged client certificates that match a whitelisted issuer and serial
Technology
RabbitMQ
CVSS Score
9.1 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
The rabbitmq_trust_store plugin installs a verify_fun that overrides unknown_ca and selfsigned_peer errors when the presented certificate matches a whitelisted one. The match uses only the issuer name and serial number read from the presented certificate, with no key, fingerprint or signature check. An attacker who knows the issuer and serial of any whitelisted certificate, which are not secret, can pass TLS client authentication with a forged self-signed certificate. Precondition: the trust store plugin enabled and used for peer verification.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.