CVE-2026-67404
RabbitMQ OAuth 2 plugin skips TLS verification of the JWKS endpoint when no CA bundle is available
Technology
RabbitMQ
CVSS Score
9.2 / 10.0
Affected Versions
3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5
Upstream Fix
4.2.6 and 4.3.0 (public); 3.13.15, 4.0.20, 4.1.11 (commercial)
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
When the OAuth 2 plugin has no cacertfile configured and the operating system CA bundle is empty or unreadable, as in some minimal containers, the broker falls back to verify_none when it fetches signing keys from the identity provider's JWKS endpoint, and logs no warning. An attacker in a man-in-the-middle position can serve forged keys, and the broker then accepts JWTs the attacker signed. Preconditions: the OAuth 2 plugin in use, no cacertfile, no readable OS CA bundle, and a network position between the broker and the JWKS endpoint.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.14; 4.0.0 to 4.0.19; 4.1.0 to 4.1.10; 4.2.0 to 4.2.5, you need this patch. Book a discovery call to get covered.