CVE-2026-67409 — RabbitMQ is a messaging and streaming broker.
Description
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252). the JWKS key fetching mechanism in uaajwt.erl does not validate the HTTP response status code when downloading signing keys from the OAuth2 provider's JWKS endpoint. Non-200 responses (including 4xx and 5xx errors) are processed identically to successful responses. When the JWKS endpoint returns an error response with a valid-JSON body that lacks a keys field, all previously cached signing keys are destroyed, causing a persistent authentication denial of Files: deps/rabbitmqauthbackendoauth2/src/uaajwt.erl, lines 50-63 deps/rabbitmqauthbackendoauth2/src/uaajwks.erl, lines 5-7 deps/rabbitmqauthbackendoauth2/src/rabbitoauth2provider.erl, lines 98-107 Bug 1: HTTP status code ignored (uaajwt.erl:50-63): The Erlang httpc module returns {ok, {{HttpVersion, StatusCode, ReasonPhrase}, Headers, Body}}. The pattern {ok, {, , JwksBody}} matches ANY successful HTTP transaction Persistent authentication DoS: Once keys are destroyed, ALL OAuth2/JWT authentication fails for all users until a new successful JWKS refresh occurs Amplification: A single attacker can deny access to all legitimate OAuth2 users across the entire RabbitMQ. This issue is fixed in versions 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHigh severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- broadcom
- Product
- rabbitmq server
Versions
- >= 3.13.0, < 3.13.18
- >= 4.0.0, < 4.0.23
- >= 4.1.0, < 4.1.14
- >= 4.2.0, < 4.2.9
- >= 4.3.0, < 4.3.3
Stated as the source expressed them.
References
Related threats
same CWE or vendorCVE-2026-106436 — The BSON encoder in the MongoDB PHP Driver does not check some return values after a document exceeds libbson's size limit.
CVE-2026-106436 · 3h ago
CVE-2026-18397 — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesse…
CVE-2026-18397 · 7d ago
CVE-2026-95316 — Unchecked return value in Performance in Google Chrome prior to 154.0.8037.57 allowed a local attacker to potentially read memory via a local program.
CVE-2026-95316 · 9d ago
CVE-2026-67421 — RabbitMQ is a messaging and streaming broker.
CVE-2026-67421 · 13d ago
CVE-2026-67412 — RabbitMQ is a messaging and streaming broker.
CVE-2026-67412 · 13d ago
CVE-2026-67411 — RabbitMQ is a messaging and streaming broker.
CVE-2026-67411 · 13d ago