RabbitMQ 3.13.x < 3.13.18 / 4.0.x < 4.0.23 / 4.1.x < 4.1.14 / 4.2.x < 4.2.9 / 4.3.x < 4.3.3 Multiple Vulnerabilities

high Nessus Plugin ID 362548

Synopsis

The RabbitMQ installed on the remote host is affected by multiple vulnerabilities.

Description

The version of RabbitMQ installed on the remote host is 3.13.x prior to 3.13.18, or 4.0.x prior to 4.0.23, or 4.1.x prior to 4.1.14, or 4.2.x prior to 4.2.9, or 4.3.x prior to 4.3.3. It is, therefore, affected by multiple vulnerabilities:

- The JWKS key fetching mechanism in uaa_jwt.erl does not validate the HTTP response status code when downloading signing keys from the OAuth 2 provider's JWKS endpoint. Non-200 responses are processed identically to successful ones, so an error body that lacks a keys field destroys all previously cached signing keys, causing a persistent authentication denial of service for all OAuth 2 and JWT users. (CVE-2026-67409)

- The LDAP authentication backend performs literal string substitution of ${username} into user_dn_pattern without applying RFC 4514 DN escaping. Special characters in the username are not escaped, so a crafted username can shift the bind DN into a different organizational unit and potentially resolve to a different, more privileged directory entry. (CVE-2026-67223)

- The stream management UI renders the TLS peer certificate subject and issuer distinguished names without output escaping, allowing an attacker who can obtain a certificate signed by a CA that the stream TLS listener trusts, with an attacker-chosen DN, to store script that executes when an operator views the stream connection detail page.
(CVE-2026-67239)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to RabbitMQ version 3.13.18, 4.0.23, 4.1.14, 4.2.9, 4.3.3, or later.

See Also

http://www.nessus.org/u?1c6853b1

http://www.nessus.org/u?bc637408

http://www.nessus.org/u?fee12853

Plugin Details

Severity: High

ID: 362548

File Name: rabbitmq_3_13_18.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 10/2/2026

Updated: 10/2/2026

Configuration: Enable paranoid mode, Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.6

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-67409

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4

Risk Factor: High

Base Score: 8.2

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:pivotal_software:rabbitmq, cpe:/a:vmware:rabbitmq

Required KB Items: installed_sw/RabbitMQ, Settings/ParanoidReport

Patch Publication Date: 7/22/2026

Vulnerability Publication Date: 7/22/2026

Reference Information

CVE: CVE-2026-67223, CVE-2026-67239, CVE-2026-67409