CVE-2026-67405: CWE-1385: Missing Origin Validation in WebSockets in rabbitmq rabbitmq-server
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl:102) validates the Origin header on the WebSocket upgrade. Under ssl_cert_login=true, the browser presents the client certificate automatically, so an attacker's JavaScript running in the victim's browser can authenticate as the victim. Preconditions include The non-default configuration use_http_auth=true (Web-STOMP) or ssl_cert_login=true (both plugins) must be enabled. The issue is harmless under the default in-band CONNECT credential configuration.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
AI Analysis
Technical Summary
RabbitMQ's Web-MQTT and Web-STOMP WebSocket handlers prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 lack validation of the Origin header during WebSocket upgrade requests. When the ssl_cert_login=true setting is enabled, browsers automatically present client certificates, enabling malicious JavaScript running in the victim's browser to authenticate as that victim. This vulnerability requires non-default configurations: use_http_auth=true for Web-STOMP or ssl_cert_login=true for both plugins. Under default in-band CONNECT credential configuration, the vulnerability is harmless. The flaw is tracked as CWE-1385 (Missing Origin Validation).
Potential Impact
An attacker with JavaScript execution in a victim's browser can exploit this vulnerability to authenticate as the victim to the RabbitMQ server when ssl_cert_login=true is enabled, potentially gaining unauthorized access to messaging services. The impact is limited to non-default configurations and does not affect default setups. No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in rabbitmq-server versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0. Users should upgrade to these or later versions to remediate the issue. If upgrading is not immediately possible, review and consider disabling the non-default configurations use_http_auth=true and ssl_cert_login=true to reduce risk. Patch status is confirmed fixed in the stated versions.
CVE-2026-67405: CWE-1385: Missing Origin Validation in WebSockets in rabbitmq rabbitmq-server
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the Web-MQTT handler (deps/rabbitmq_web_mqtt/src/rabbit_web_mqtt_handler.erl:104) nor the Web-STOMP handler (deps/rabbitmq_web_stomp/src/rabbit_web_stomp_handler.erl:102) validates the Origin header on the WebSocket upgrade. Under ssl_cert_login=true, the browser presents the client certificate automatically, so an attacker's JavaScript running in the victim's browser can authenticate as the victim. Preconditions include The non-default configuration use_http_auth=true (Web-STOMP) or ssl_cert_login=true (both plugins) must be enabled. The issue is harmless under the default in-band CONNECT credential configuration.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
CVSS v4.0
Score 5.3medium
Affected software
rabbitmq
rabbitmq-server
pkg:github/rabbitmq/rabbitmq-serverRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RabbitMQ's Web-MQTT and Web-STOMP WebSocket handlers prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 lack validation of the Origin header during WebSocket upgrade requests. When the ssl_cert_login=true setting is enabled, browsers automatically present client certificates, enabling malicious JavaScript running in the victim's browser to authenticate as that victim. This vulnerability requires non-default configurations: use_http_auth=true for Web-STOMP or ssl_cert_login=true for both plugins. Under default in-band CONNECT credential configuration, the vulnerability is harmless. The flaw is tracked as CWE-1385 (Missing Origin Validation).
Potential Impact
An attacker with JavaScript execution in a victim's browser can exploit this vulnerability to authenticate as the victim to the RabbitMQ server when ssl_cert_login=true is enabled, potentially gaining unauthorized access to messaging services. The impact is limited to non-default configurations and does not affect default setups. No known exploits in the wild have been reported.
Mitigation Recommendations
This vulnerability is fixed in rabbitmq-server versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0. Users should upgrade to these or later versions to remediate the issue. If upgrading is not immediately possible, review and consider disabling the non-default configurations use_http_auth=true and ssl_cert_login=true to reduce risk. Patch status is confirmed fixed in the stated versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-29T15:02:20.411Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab43b0df7a7c54106517563
Added to database: 09/23/2026, 20:48:13 UTC
Last enriched: 09/23/2026, 21:02:53 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.