Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67236

RabbitMQ management UI login cookie holds the username and password in base64

Technology

RabbitMQ

CVSS Score

8.2 / 10.0

Affected Versions

4.2.0 to 4.2.7; 4.3.0 to 4.3.1

Upstream Fix

4.2.8 and 4.3.2 (public)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

From 4.2.0, a successful POST /login set an authentication cookie containing the base64-encoded username:password, with no HttpOnly, Secure, SameSite or expiry attributes. Base64 is an encoding, not encryption, so anyone who can read the cookie through same-origin cross-site scripting, plain HTTP traffic or the browser's cookie store recovers the login credentials.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.2.0 to 4.2.7; 4.3.0 to 4.3.1, you need this patch. Book a discovery call to get covered.