CVE-2026-67237
RabbitMQ management UI writes bearer tokens unescaped into the OAuth bootstrap JavaScript
Technology
RabbitMQ
CVSS Score
7.5 / 10.0
Affected Versions
4.2.0 to 4.2.7; 4.3.0 to 4.3.1
Upstream Fix
4.2.8 and 4.3.2 (public)
Published
September 25, 2026
OSSeva Coverage
Fixed upstream
Description
The management UI inserted a bearer token from the Authorization header or the access_token cookie into the OAuth bootstrap JavaScript without escaping, so attacker-controlled token content could run script in the management UI origin. The endpoint is reachable before authentication only when management.oauth_enabled is true, and the cookie route also needs the attacker to plant a cookie on the management host.
Is your RabbitMQ deployment affected?
If you're running 4.2.0 to 4.2.7; 4.3.0 to 4.3.1, you need this patch. Book a discovery call to get covered.