RabbitMQ is a widely deployed enterprise messaging broker; an attacker can induce cluster-wide OAuth/JWT authentication outages, disrupting applications and services.
CVE-2026-67409
RabbitMQ JWKS fetch ignores HTTP status, causing persistent OAuth/JWT authentication DoS.
Is CVE-2026-67409 being exploited?
Not confirmed. CVE-2026-67409 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked.
How severe is CVE-2026-67409?
CVE-2026-67409 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-67409?
Yes. A fix has been recorded for CVE-2026-67409. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-67409 affect?
CVE-2026-67409 affects RabbitMQ Server 3.13.0–3.13.17, RabbitMQ Server 4.0.0–4.0.22, 4.1.0–4.1.13, 4.2.0–4.2.8, and 1 further product or version. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-67409?
Upgrade to fixed versions (see advisory) and monitor JWKS responses; validate JWKS endpoint availability.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Persistent authentication denial-of-service: JWKS error responses wipe cached signing keys, blocking all OAuth2/JWT auth until a successful refresh.
Patch when possible
- affected>= 4.3.0 and < 4.3.3
- affected>= 4.2.0 and < 4.2.9
- affected>= 4.1.0 and < 4.1.14
- affected>= 4.0.0 and < 4.0.23
- affected>= 3.13.0 and < 3.13.18
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.