CVE-2026-67239: Rabbitmq Rabbitmq-Server

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110 render peercertsubject / peercertissuer with raw <%= %> and no fmtstring(). RFC4514 backslash-escaping of </> is HTML-inert and bypassable (<img ... //>). Requires non-default config: a stream TLS listener with verifypeer and an attacker-obtainable trusted cert with a malicious Same as the connection.ejs finding, against operators viewing the stream-connection detail rabbitmqstream + rabbitmqstreammanagement enabled with a TLS listener using verifypeer Attacker can obtain a certificate signed by a CA the listener trusts, with attacker-chosen DN An operator views the. This issue is fixed in versions 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3.

Affected products

  • Rabbitmq Rabbitmq-Server: from 3.13.0, before 3.13.18 (fixed in 3.13.18); from 4.0.0, before 4.0.23 (fixed in 4.0.23); from 4.1.0, before 4.1.14 (fixed in 4.1.14); from 4.2.0, before 4.2.9 (fixed in 4.2.9); from 4.3.0, before 4.3.3 (fixed in 4.3.3)

Published 2026-09-25. Last modified 2026-09-28.