Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67237

RabbitMQ management UI writes bearer tokens unescaped into the OAuth bootstrap JavaScript

Technology

RabbitMQ

CVSS Score

7.5 / 10.0

Affected Versions

4.2.0 to 4.2.7; 4.3.0 to 4.3.1

Upstream Fix

4.2.8 and 4.3.2 (public)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

The management UI inserted a bearer token from the Authorization header or the access_token cookie into the OAuth bootstrap JavaScript without escaping, so attacker-controlled token content could run script in the management UI origin. The endpoint is reachable before authentication only when management.oauth_enabled is true, and the cookie route also needs the attacker to plant a cookie on the management host.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 4.2.0 to 4.2.7; 4.3.0 to 4.3.1, you need this patch. Book a discovery call to get covered.