CVE-2026-67239
Stored XSS in the RabbitMQ stream management UI through a TLS client certificate DN
Technology
RabbitMQ
CVSS Score
7.6 / 10.0
Affected Versions
3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2
Upstream Fix
4.2.9 and 4.3.3 (public); 3.13.18, 4.0.23, 4.1.14 (commercial)
Published
September 25, 2026
OSSeva Coverage
Fixed upstream
Description
The stream connection page renders the peer certificate subject and issuer without HTML escaping. An attacker holding a certificate from a CA the stream TLS listener trusts, with a DN of their choosing, can run script in an operator's browser when the operator opens that connection. Preconditions: the stream and stream management plugins enabled, with a TLS listener using verify_peer.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2, you need this patch. Book a discovery call to get covered.