CVE-2026-67411Medium· 6.0▾ TwilightPoC availableRabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before th…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before the MQTT authentication path checked loopback_users, causing the frontend-to-broker address to be treated as loopback. An attacker who can reach the trusted frontend and has valid credentials for a loopback-restricted account can therefore bypass the source-address restriction; the issue does not bypass password authentication. This issue is fixed in versions 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-67409High· 8.2RabbitMQ is a messaging and streaming broker
CVE-2026-67410High· 8.2RabbitMQ is a messaging and streaming broker
CVE-2026-67412Medium· 6.0RabbitMQ is a messaging and streaming broker
CVE-2026-67241Medium· 4.8RabbitMQ is a messaging and streaming broker
CVE-2026-67223Medium· 6.3RabbitMQ is a messaging and streaming broker
CVE-2026-67242Medium· 6.3RabbitMQ is a messaging and streaming broker