Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-67236
RabbitMQ management UI login cookie holds the username and password in base64
Technology
RabbitMQ
CVSS Score
8.2 / 10.0
Affected Versions
4.2.0 to 4.2.7; 4.3.0 to 4.3.1
Upstream Fix
4.2.8 and 4.3.2 (public)
Published
September 25, 2026
OSSeva Coverage
Fixed upstream
Description
From 4.2.0, a successful POST /login set an authentication cookie containing the base64-encoded username:password, with no HttpOnly, Secure, SameSite or expiry attributes. Base64 is an encoding, not encryption, so anyone who can read the cookie through same-origin cross-site scripting, plain HTTP traffic or the browser's cookie store recovers the login credentials.
Is your RabbitMQ deployment affected?
If you're running 4.2.0 to 4.2.7; 4.3.0 to 4.3.1, you need this patch. Book a discovery call to get covered.