Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-66077— RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI

Quick assessment

Affected
rabbitmq rabbitmq-server
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RabbitMQ 是一种消息和流式传输代理。在 3.13.15、4.0.20、4.1.11 和 4.2.6 版本之前,管理 UI 使用了 EJS 1.0,其中 标签不会进行 HTML 转义。 直接将 (以及 )渲染到页面中。相同模式也出现在 中。这些值来自 ,后者将 DN 格式化为字符串而不会进行 HTML 转义。验证者纠正了原始研究人员的说法:这只有在监听器配置为 时才可访问(因此证书必须由代理的信任存储中的 CA 签名,而不是任意自签名证书);然而,在使用 mTLS 进行客户端身份验证的部署中,任何能够从组织

CVSS 7.3 · High EPSS 0.30% · P20
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-66077

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RabbitMQ: Stored XSS via TLS peer-certificate DN in management UI
Source: CVE Program / CVE List V5
Vulnerability Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_subject %> (and peer_cert_issuer) directly into the page. The same pattern appears in streamConnection.ejs:102,106,110. The values come from rabbit_ssl:peer_cert_subject/1 which formats the DN as a string without HTML escaping. The verifier corrected the original researcher's claim: this is reachable only when the listener is configured with verify_peer (so the certificate must be signed by a CA in the broker's trust store, not arbitrary self-signed); however, in deployments using mTLS for client authentication, any user who can request a certificate from the organisational CA controls the Subject CN. An attacker who can obtain a TLS client certificate signed by a CA the broker trusts (with verify_peer enabled) can embed JavaScript in the certificate's Subject DN. When any administrator views that connection in the management UI, the script executes in the admin's browser session, allowing full account takeover (create users, export definitions, etc.). The management UI's CSP includes 'unsafe-inline', so inline script execution is not blocked. Preconditions include TLS listener configured with ssl_options.verify = verify_peer Attacker can obtain a CA-signed client certificate with attacker-chosen Subject (e.g. self-service corporate PKI, or rabbitmq_trust_store plugin in use) Administrator views the connection detail page. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rabbitmq rabbitmq-server >= 3.13.0, < 3.13.15 -

II. Public POCs for CVE-2026-66077

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66077

请登录查看更多情报信息。

Vendor Pages for CVE-2026-66077 (1)

Other References for CVE-2026-66077 (1)

Same Patch Batch · rabbitmq · 2026-09-23 · 25 CVEs total

CVE-2026-67404 9.2 CRITICAL RabbitMQ: OAuth2 silent verify_none fallback for JWKS fetch
CVE-2026-67231 9.1 CRITICAL RabbitMQ: Trust-store whitelist by Issuer+Serial only
CVE-2026-66079 8.2 HIGH RabbitMQ: Pre-auth AMQP 1.0 array32 zero-width element DoS
CVE-2026-67232 8.2 HIGH RabbitMQ: Web-MQTT decompression bomb
CVE-2026-66070 7.6 HIGH RabbitMQ: CORS * reflects Origin with Allow-Credentials
CVE-2026-67235 7.1 HIGH RabbitMQ: AMQP 0-9-1 body assembly never validates accumulated size
CVE-2026-67238 7.1 HIGH RabbitMQ: Atom-table exhaustion via reply-to queue name decoding
CVE-2026-67228 6.9 MEDIUM RabbitMQ: Atom exhaustion: to_atom on runtime-parameter component
CVE-2026-67229 6.9 MEDIUM RabbitMQ: Admin-only atom exhaustion: atomize_keys on vhost metadata
CVE-2026-67219 6.0 MEDIUM RabbitMQ: Consistent-hash exchange unbounded weight
CVE-2026-67220 6.0 MEDIUM RabbitMQ: JMS topic exchange erl_scan atom exhaustion
CVE-2026-66067 6.0 MEDIUM RabbitMQ: Stream protocol skips per vhost per user connection limits
CVE-2026-66074 6.0 MEDIUM RabbitMQ: ReDoS via management API ?name= filter
CVE-2026-66072 6.0 MEDIUM RabbitMQ: Atom table exhaustion via stream `chunk_selector`
CVE-2026-66080 5.9 MEDIUM RabbitMQ: Super-stream partitions unbounded allocation
CVE-2026-67221 5.9 MEDIUM RabbitMQ: AMQP 1.0 shovel status exposes plaintext URI passwords
CVE-2026-66068 5.6 MEDIUM RabbitMQ: Shovel DEBUG log of full state exposes decrypted URIs
CVE-2026-67405 5.3 MEDIUM RabbitMQ: CSWSH on Web-STOMP / Web-MQTT (no Origin validation)
CVE-2026-66069 2.3 LOW RabbitMQ: Monitoring-tag DELETE of auth-attempt metrics
CVE-2026-66076 2.3 LOW RabbitMQ: Cross-vhost quorum-queue status and stream tracking disclosure

Showing top 20 of 25 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-66077

No comments yet


Leave a comment