CVE-2026-67231: Rabbitmq Rabbitmq-Server

Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The trust-store plugin installs a verify_fun that overrides {bad_cert, unknown_ca} / {bad_cert, selfsigned_peer} when the presented cert "matches" a whitelisted one. The match key is extract_issuer_id/1 → public_key:pkix_issuer_id/2 → {IssuerName, SerialNumber} , both fields are taken verbatim from the presented certificate body and contain no public-key, SKI, fingerprint or signature material. is_whitelisted/1 is a pure ets:member lookup; the stored full DER is used only for list/0 display and is never compared against the presented cert. cacerts is [], so the whitelisted cert is never used as a trust anchor for path validation either. TLS client-authentication bypass: an attacker who knows the issuer DN + serial of any whitelisted certificate can connect with a forged self-signed cert. Preconditions include rabbitmq_trust_store plugin enabled and used as the TLS verify_fun Attacker knows or can guess the {Issuer, Serial} of at least one whitelisted cert (non-secret; exposed via CLI/logs/any cert copy). This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

Affected products

  • Rabbitmq Rabbitmq-Server: from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 4.0.0, before 4.0.20 (fixed in 4.0.20); from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.6 (fixed in 4.2.6)

Published 2026-09-23. Last modified 2026-09-29.