Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67239

Stored XSS in the RabbitMQ stream management UI through a TLS client certificate DN

Technology

RabbitMQ

CVSS Score

7.6 / 10.0

Affected Versions

3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2

Upstream Fix

4.2.9 and 4.3.3 (public); 3.13.18, 4.0.23, 4.1.14 (commercial)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

The stream connection page renders the peer certificate subject and issuer without HTML escaping. An attacker holding a certificate from a CA the stream TLS listener trusts, with a DN of their choosing, can run script in an operator's browser when the operator opens that connection. Preconditions: the stream and stream management plugins enabled, with a TLS listener using verify_peer.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2, you need this patch. Book a discovery call to get covered.