目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-66077— RabbitMQ 管理界面存储型XSS漏洞

一分钟漏洞结论

影响对象
rabbitmq rabbitmq-server
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

RabbitMQ 是一种消息和流式传输代理。在 3.13.15、4.0.20、4.1.11 和 4.2.6 版本之前,管理 UI 使用了 EJS 1.0,其中 标签不会进行 HTML 转义。 直接将 (以及 )渲染到页面中。相同模式也出现在 中。这些值来自 ,后者将 DN 格式化为字符串而不会进行 HTML 转义。验证者纠正了原始研究人员的说法:这只有在监听器配置为 时才可访问(因此证书必须由代理的信任存储中的 CA 签名,而不是任意自签名证书);然而,在使用 mTLS 进行客户端身份验证的部署中,任何能够从组织

CVSS 7.3 · High EPSS 0.30% · P20
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-66077 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
来源: CVE Program / CVE List V5
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_subject %> (and peer_cert_issuer) directly into the page. The same pattern appears in streamConnection.ejs:102,106,110. The values come from rabbit_ssl:peer_cert_subject/1 which formats the DN as a string without HTML escaping. The verifier corrected the original researcher's claim: this is reachable only when the listener is configured with verify_peer (so the certificate must be signed by a CA in the broker's trust store, not arbitrary self-signed); however, in deployments using mTLS for client authentication, any user who can request a certificate from the organisational CA controls the Subject CN. An attacker who can obtain a TLS client certificate signed by a CA the broker trusts (with verify_peer enabled) can embed JavaScript in the certificate's Subject DN. When any administrator views that connection in the management UI, the script executes in the admin's browser session, allowing full account takeover (create users, export definitions, etc.). The management UI's CSP includes 'unsafe-inline', so inline script execution is not blocked. Preconditions include TLS listener configured with ssl_options.verify = verify_peer Attacker can obtain a CA-signed client certificate with attacker-chosen Subject (e.g. self-service corporate PKI, or rabbitmq_trust_store plugin in use) Administrator views the connection detail page. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
rabbitmq rabbitmq-server >= 3.13.0, < 3.13.15 -

二、漏洞 CVE-2026-66077 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-66077 的情报信息

请登录查看更多情报信息。

CVE-2026-66077 厂商页面 (1)

CVE-2026-66077 其他参考 (1)

同批安全公告 · rabbitmq · 2026-09-23 · 共 25 条

CVE-2026-67404 9.2 CRITICAL RabbitMQ OAuth2 JWKS获取中verify_none回退漏洞
CVE-2026-67231 9.1 CRITICAL RabbitMQ 证书信任存储白名单漏洞
CVE-2026-66079 8.2 HIGH RabbitMQ AMQP 1.0 零宽度元素DoS漏洞
CVE-2026-67232 8.2 HIGH RabbitMQ Web-MQTT解压炸弹漏洞
CVE-2026-66070 7.6 HIGH RabbitMQ CORS允许凭证反射Origin漏洞
CVE-2026-67235 7.1 HIGH RabbitMQ AMQP 0-9-1 body 组装未验证累计大小漏洞
CVE-2026-67238 7.1 HIGH RabbitMQ 回复队列名解码导致原子表耗尽漏洞
CVE-2026-67228 6.9 MEDIUM RabbitMQ atom耗尽漏洞
CVE-2026-67229 6.9 MEDIUM RabbitMQ vhost元数据原子耗尽漏洞
CVE-2026-67219 6.0 MEDIUM RabbitMQ 一致哈希交换器无界权重漏洞
CVE-2026-67220 6.0 MEDIUM RabbitMQ JMS主题交换导致Erlang扫描原子耗尽漏洞
CVE-2026-66067 6.0 MEDIUM RabbitMQ 流协议跳过每虚拟主机每用户连接限制
CVE-2026-66074 6.0 MEDIUM RabbitMQ管理API名称过滤正则拒绝服务漏洞
CVE-2026-66072 6.0 MEDIUM RabbitMQ stream chunk_selector导致Atom表耗尽漏洞
CVE-2026-66080 5.9 MEDIUM RabbitMQ 超级流分区无限分配漏洞
CVE-2026-67221 5.9 MEDIUM RabbitMQ AMQP 1.0 明文URI密码泄露
CVE-2026-66068 5.6 MEDIUM RabbitMQ Shovel 调试日志泄露解密URI漏洞
CVE-2026-67405 5.3 MEDIUM RabbitMQ Web-STOMP/Web-MQTT 无来源验证漏洞
CVE-2026-66069 2.3 LOW RabbitMQ auth-attempt指标监控标签DELETE漏洞
CVE-2026-66076 2.3 LOW RabbitMQ 跨虚拟主机队列状态与流跟踪信息泄露漏洞

显示前 20 条,共 25 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-66077

暂无评论


发表评论