boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-67421

RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   L   A   L   L   N    4.5   .0028   18.7     —
AFFECTED
  Product          Versions                Fixed
  rabbitmq-server  >= 3.13.0, < 3.13.19 –  —
TIMELINE
  Jul 29  Reserved by GitHub_M
  Sep 25  Published (CNA: GitHub_M)
  Oct 6   EXPLOIT PUBLISHED — CVE-2026-67421 (rabbitmq-server). Public exploit reference added.
CWE-862 · CNA: GitHub_M · CVSS v4.0 · 3 references · NVD status: Analyzed

Description

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management UI was enabled. Exploitation requires an attacker with queue configure permission, a management administrator who can see but cannot read that queue, and the administrator clicking Get Message(s). A queue name containing a base element can then retarget the automatic relative refresh because the Content Security Policy omits base-uri and connect-src, and an attacker endpoint that permits the management origin through CORS can receive the victim's Authorization header. This issue is fixed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 29, 2026ReservedReserved by GitHub_M
September 25, 2026PublishedPublished (CNA: GitHub_M)
October 6, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-67421 (rabbitmq-server). Public exploit reference added.

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
rabbitmqrabbitmq-server—>= 3.13.0, < 3.13.19—

Weaknesses

CWE-862

References (3)

Related

Authoritative record: CVE-2026-67421 at cve.org

Vendors: rabbitmq

Weaknesses: CWE-862

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-67421 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.