CVE-2026-67239
RabbitMQ: Stored XSS via TLS peer-certificate DN in stream-management UI
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110 render peercertsubject / peercertissuer with raw <%= %> and no fmtstring(). RFC4514 backslash-escaping of </> is HTML-inert and bypassable (<img ... //>). Requires non-default config: a stream TLS listener with verifypeer and an attacker-obtainable trusted cert with a malicious Same as the connection.ejs finding, against operators viewing the stream-connection detail rabbitmqstream + rabbitmqstreammanagement enabled with a TLS listener using verifypeer Attacker can obtain a certificate signed by a CA the listener trusts, with attacker-chosen DN An operator views the. This issue is fixed in versions 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3.
| CWE | CWE-79 |
| Vendor | rabbitmq |
| Product | rabbitmq-server |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Get instant alerts for rabbitmq rabbitmq-server
Be the first to know when new unknown vulnerabilities affecting rabbitmq rabbitmq-server are published โ delivered to Slack, Telegram or Discord.