Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-67404

RabbitMQ OAuth 2 plugin skips TLS verification of the JWKS endpoint when no CA bundle is available

Technology

RabbitMQ

CVSS Score

9.2 / 10.0

Affected Versions

3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5

Upstream Fix

4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

When the OAuth 2 plugin has no cacertfile configured and the operating system CA bundle is empty or unreadable, as in some minimal containers, the broker falls back to verify_none when it fetches signing keys from the identity provider's JWKS endpoint, and logs no warning. An attacker in a man-in-the-middle position can serve forged keys, and the broker then accepts JWTs the attacker signed. Preconditions: the OAuth 2 plugin in use, no cacertfile, no readable OS CA bundle, and a network position between the broker and the JWKS endpoint.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.