Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-67409

RabbitMQ OAuth 2 backend ignores the HTTP status of JWKS responses, so an error response wipes the signing keys

Technology

RabbitMQ

CVSS Score

8.2 / 10.0

Affected Versions

3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2

Upstream Fix

4.2.9 and 4.3.3 (public); 3.13.18, 4.0.23, 4.1.14 (commercial)

Published

September 25, 2026

OSSeva Coverage

Fixed upstream

Description

The OAuth 2 backend does not check the HTTP status code when it downloads signing keys from the identity provider's JWKS endpoint. A 4xx or 5xx response with a JSON body that lacks a keys field replaces the cached keys, after which every OAuth 2 and JWT authentication fails until a later refresh succeeds. The advisory notes that one attacker can deny access to all OAuth 2 users of the broker this way.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.17; 4.0.0 to 4.0.22; 4.1.0 to 4.1.13; 4.2.0 to 4.2.8; 4.3.0 to 4.3.2, you need this patch. Book a discovery call to get covered.