Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (29)
📋 Description
CVE-2026-44839 — rabbitmq-server: RabbitMQ: Unsanitized vhost names allow for XSS in management UI CVE-2026-66067 — rabbitmq: RabbitMQ: Authenticated user can bypass connection limits via stream protocol CVE-2026-66068 — rabbitmq: RabbitMQ: Information disclosure of decrypted Shovel URIs in debug logs CVE-2026-66069 — rabbitmq-server: RabbitMQ: Monitoring user can reset authentication attempt counters CVE-2026-66070 — rabbitmq-server: RabbitMQ: Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions CVE-2026-66072 — rabbitmq-server: RabbitMQ: Denial of Service via atom table exhaustion in stream chunk_selector CVE-2026-66074 — rabbitmq: RabbitMQ: Denial of Service via management API regular expression filter CVE-2026-66075 — rabbitmq-server: RabbitMQ: Monitoring user can disrupt message flow via authorization flaw CVE-2026-66076 — rabbitmq: RabbitMQ: Information disclosure via cross-vhost authorization bypass CVE-2026-66077 — RabbitMQ: RabbitMQ: Account takeover via stored Cross-Site Scripting in TLS peer-certificate DN CVE-2026-66079 — rabbitmq-server: RabbitMQ: Denial of Service via AMQP 1.0 array32 parsing CVE-2026-66080 — rabbitmq-server: RabbitMQ: Denial of Service via unbounded super-stream partition allocation CVE-2026-67218 — rabbitmq-server: RabbitMQ: Privilege escalation via super-stream HTTP creation CVE-2026-67219 — rabbitmq: RabbitMQ: Denial of Service via unbounded consistent-hash exchange weight CVE-2026-67220 — rabbitmq-server: RabbitMQ: Denial of Service via JMS topic exchange atom exhaustion CVE-2026-67221 — rabbitmq: RabbitMQ: Information disclosure of AMQP 1.0 shovel URI passwords CVE-2026-67224 — rabbitmq: RabbitMQ: Administrator path traversal allows arbitrary file write CVE-2026-67228 — rabbitmq: RabbitMQ: Denial of Service via atom exhaustion in runtime-parameter component CVE-2026-67229 — RabbitMQ: RabbitMQ: Denial of Service via admin-only atom exhaustion from crafted vhost metadata CVE-2026-67232 — rabbitmq: rabbitmq_web_mqtt: RabbitMQ Web-MQTT plugin: Denial of Service via decompression bomb CVE-2026-67233 — rabbitmq-server: RabbitMQ: Privilege escalation allows monitoring users to delete shovels CVE-2026-67235 — rabbitmq-server: RabbitMQ: Denial of Service via AMQP 0-9-1 body size validation bypass CVE-2026-67238 — rabbitmq-server: RabbitMQ: Denial of Service due to atom-table exhaustion via reply-to queue name decoding CVE-2026-67240 — RabbitMQ: RabbitMQ: Denial of Service via crafted AMQP 1.0 SQL LIKE filter CVE-2026-67241 — rabbitmq-server: rabbitmq-server: Unauthorized message routing via missing alternate-exchange permission check CVE-2026-67242 — rabbitmq-server: rabbitmq-server: Authentication bypass via improper validation of floating-point token expiration timestamps CVE-2026-67405 — rabbitmq-server: RabbitMQ: Cross-Site WebSocket Hijacking via missing Origin header validation CVE-2026-67412 — rabbitmq-server: RabbitMQ: Unauthorized cross-vhost message access via missing Federation upstream authorization CVE-2026-67420 — rabbitmq-server: rabbitmq-server: Unauthorized user impersonation via stale OAuth token refresh
🎯 Affected products4
- Red Hat Hardened Images
- rabbitmq-server4.3-0:4.3.6-1.hum1@aarch64 as a component of Red Hat Hardened Images
- rabbitmq-server4.3-0:4.3.6-1.hum1@src as a component of Red Hat Hardened Images
- rabbitmq-server4.3-0:4.3.6-1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, restrict access to the RabbitMQ management UI to trusted administrators only. Ensure that administrative interfaces are not exposed to untrusted networks. Workaround: Restrict Management API access and monitoring-tag accounts, or disable the Management plugin where it is not needed. Workaround: Replace wildcard CORS with explicit trusted origins and avoid administrator Basic credentials in browsers used for untrusted sites. Workaround: Disable the stream plugin if unused, and restrict stream access to trusted clients. Workaround: Restrict monitoring access and disable federation management where it is not needed. Workaround: Restrict untrusted network access to AMQP listeners; disable AMQP 1.0 support if unused. Workaround: Restrict management-tagged accounts and disable stream management where it is not needed. Workaround: Restrict that access or disable stream management where it is not needed. Workaround: Disable the JMS topic exchange plugin if unused and restrict binding permissions to trusted users. Workaround: Disable the shovel management extension on brokers that do not need to manage shovels over HTTP. Enable rabbitmq_shovel explicitly first so it stays active if it was only pulled in as a dependency: rabbitmq-plugins enable rabbitmq_shovel rabbitmq-plugins disable rabbitmq_shovel_management This removes the /api/shovels endpoint. Accounts with the policymaker or administrator tag can still delete shovels through /api/parameters, which enforces the correct role check. If the endpoint has to stay available, remove the monitoring tag from any account that should not be able to stop message flow. Workaround: Restrict publish access to trusted clients; broker memory alarms offer only partial protection until an updated build is deployed. Workaround: Restrict AMQP access to trusted clients until an updated build is deployed. Workaround: Disable Web-STOMP and Web-MQTT where unnecessary, or avoid those non-default authentication options until an updated build is deployed.
🔗 References (58)
- selfhttps://access.redhat.com/errata/RHSA-2026:67552
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-44839
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-67221
- externalhttps://access.redhat.com/security/cve/CVE-2026-67219
- externalhttps://access.redhat.com/security/cve/CVE-2026-67224
- externalhttps://access.redhat.com/security/cve/CVE-2026-67232
- externalhttps://access.redhat.com/security/cve/CVE-2026-66067
- externalhttps://access.redhat.com/security/cve/CVE-2026-66077
- externalhttps://access.redhat.com/security/cve/CVE-2026-66080
- externalhttps://access.redhat.com/security/cve/CVE-2026-67405
- externalhttps://access.redhat.com/security/cve/CVE-2026-67228
- externalhttps://access.redhat.com/security/cve/CVE-2026-67220
- externalhttps://access.redhat.com/security/cve/CVE-2026-67235
- externalhttps://access.redhat.com/security/cve/CVE-2026-66074
- externalhttps://access.redhat.com/security/cve/CVE-2026-66069
- externalhttps://access.redhat.com/security/cve/CVE-2026-66075
- externalhttps://access.redhat.com/security/cve/CVE-2026-67240
- externalhttps://access.redhat.com/security/cve/CVE-2026-66076
- externalhttps://access.redhat.com/security/cve/CVE-2026-66070
- externalhttps://access.redhat.com/security/cve/CVE-2026-66079
- externalhttps://access.redhat.com/security/cve/CVE-2026-67238
- externalhttps://access.redhat.com/security/cve/CVE-2026-66072
- externalhttps://access.redhat.com/security/cve/CVE-2026-67218
- externalhttps://access.redhat.com/security/cve/CVE-2026-66068
- externalhttps://access.redhat.com/security/cve/CVE-2026-67229
- externalhttps://access.redhat.com/security/cve/CVE-2026-67233
- externalhttps://access.redhat.com/security/cve/CVE-2026-67242
- externalhttps://access.redhat.com/security/cve/CVE-2026-67241
- externalhttps://access.redhat.com/security/cve/CVE-2026-66071
- externalhttps://access.redhat.com/security/cve/CVE-2026-67227
- externalhttps://access.redhat.com/security/cve/CVE-2026-67234
- externalhttps://access.redhat.com/security/cve/CVE-2026-67226
- externalhttps://access.redhat.com/security/cve/CVE-2026-67406
- externalhttps://access.redhat.com/security/cve/CVE-2026-67409
- externalhttps://access.redhat.com/security/cve/CVE-2026-67415
- externalhttps://access.redhat.com/security/cve/CVE-2026-67408
- externalhttps://access.redhat.com/security/cve/CVE-2026-67239
- externalhttps://access.redhat.com/security/cve/CVE-2026-67223
- externalhttps://access.redhat.com/security/cve/CVE-2026-67410
- externalhttps://access.redhat.com/security/cve/CVE-2026-66073
- externalhttps://access.redhat.com/security/cve/CVE-2026-67411
- externalhttps://access.redhat.com/security/cve/CVE-2026-67413
- externalhttps://access.redhat.com/security/cve/CVE-2026-67421
- externalhttps://access.redhat.com/security/cve/CVE-2026-67237
- externalhttps://access.redhat.com/security/cve/CVE-2026-67407
- externalhttps://access.redhat.com/security/cve/CVE-2026-61837
- externalhttps://access.redhat.com/security/cve/CVE-2026-67419
- externalhttps://access.redhat.com/security/cve/CVE-2026-67420
- externalhttps://access.redhat.com/security/cve/CVE-2026-67222
- externalhttps://access.redhat.com/security/cve/CVE-2026-66078
- externalhttps://access.redhat.com/security/cve/CVE-2026-67412
- externalhttps://access.redhat.com/security/cve/CVE-2026-67230
- externalhttps://access.redhat.com/security/cve/CVE-2026-67225
- externalhttps://access.redhat.com/security/cve/CVE-2026-67236
- externalhttps://access.redhat.com/security/cve/CVE-2026-67404
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67552.json