{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-67421","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2026-07-29T15:02:20.412Z","datePublished":"2026-09-25T16:39:02.323Z","dateUpdated":"2026-09-25T19:58:22.877Z"},"containers":{"cna":{"title":"RabbitMQ: Stored HTML Injection in RabbitMQ Management OAuth Error Handling","problemTypes":[{"descriptions":[{"cweId":"CWE-862","lang":"en","description":"CWE-862: Missing Authorization","type":"CWE"}]}],"metrics":[{"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"ACTIVE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","baseScore":4.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N","version":"4.0"}}],"references":[{"name":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr","tags":["x_refsource_CONFIRM"],"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr"},{"name":"https://github.com/rabbitmq/rabbitmq-server/commit/ff595eaaa6d4f580f72fa04801ffd35f48c46027","tags":["x_refsource_MISC"],"url":"https://github.com/rabbitmq/rabbitmq-server/commit/ff595eaaa6d4f580f72fa04801ffd35f48c46027"},{"name":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.5","tags":["x_refsource_MISC"],"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.3.5"}],"affected":[{"vendor":"rabbitmq","product":"rabbitmq-server","versions":[{"version":">= 3.13.0, < 3.13.19","status":"affected"},{"version":">= 4.0.0, < 4.0.24","status":"affected"},{"version":">= 4.1.0, < 4.1.15","status":"affected"},{"version":">= 4.2.0, < 4.2.10","status":"affected"},{"version":">= 4.3.0, < 4.3.5","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2026-09-25T16:39:02.323Z"},"descriptions":[{"lang":"en","value":"RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAuth management UI was enabled. Exploitation requires an attacker with queue configure permission, a management administrator who can see but cannot read that queue, and the administrator clicking Get Message(s). A queue name containing a base element can then retarget the automatic relative refresh because the Content Security Policy omits base-uri and connect-src, and an attacker endpoint that permits the management origin through CORS can receive the victim's Authorization header. This issue is fixed in versions 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5."}],"source":{"advisory":"GHSA-6256-27fm-4rgr","discovery":"UNKNOWN"}},"adp":[{"references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6256-27fm-4rgr","tags":["exploit"]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-25T19:57:04.069632Z","id":"CVE-2026-67421","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-25T19:58:22.877Z"}}]}}