CVE-2026-67236High· 8.2▾ TwilightRabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameS…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameSite, or expiration protections. Because base64 is encoding rather than encryption, an attacker with same-origin cross-site scripting, an HTTP-readable network position, or local access to the browser cookie store could recover the actual login credentials; older browsers that treated an absent SameSite attribute as None also sent the cookie cross-site. This issue is fixed in versions 4.2.8 and 4.3.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67234Low· 2.3RabbitMQ is a messaging and streaming broker
CVE-2026-67237High· 7.5RabbitMQ is a messaging and streaming broker
CVE-2026-67221Medium· 5.9RabbitMQ is a messaging and streaming broker
CVE-2026-67222Medium· 5.9RabbitMQ is a messaging and streaming broker
CVE-2026-67230Medium· 6.3RabbitMQ is a messaging and streaming broker
CVE-2026-66078Low· 2.1RabbitMQ is a messaging and streaming broker