RHSA-2026:67552HighCVSS 8.7

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
September 15, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (29)

📋 Description

CVE-2026-44839 — rabbitmq-server: RabbitMQ: Unsanitized vhost names allow for XSS in management UI CVE-2026-66067 — rabbitmq: RabbitMQ: Authenticated user can bypass connection limits via stream protocol CVE-2026-66068 — rabbitmq: RabbitMQ: Information disclosure of decrypted Shovel URIs in debug logs CVE-2026-66069 — rabbitmq-server: RabbitMQ: Monitoring user can reset authentication attempt counters CVE-2026-66070 — rabbitmq-server: RabbitMQ: Cross-Origin Resource Sharing (CORS) misconfiguration allows unauthorized actions CVE-2026-66072 — rabbitmq-server: RabbitMQ: Denial of Service via atom table exhaustion in stream chunk_selector CVE-2026-66074 — rabbitmq: RabbitMQ: Denial of Service via management API regular expression filter CVE-2026-66075 — rabbitmq-server: RabbitMQ: Monitoring user can disrupt message flow via authorization flaw CVE-2026-66076 — rabbitmq: RabbitMQ: Information disclosure via cross-vhost authorization bypass CVE-2026-66077 — RabbitMQ: RabbitMQ: Account takeover via stored Cross-Site Scripting in TLS peer-certificate DN CVE-2026-66079 — rabbitmq-server: RabbitMQ: Denial of Service via AMQP 1.0 array32 parsing CVE-2026-66080 — rabbitmq-server: RabbitMQ: Denial of Service via unbounded super-stream partition allocation CVE-2026-67218 — rabbitmq-server: RabbitMQ: Privilege escalation via super-stream HTTP creation CVE-2026-67219 — rabbitmq: RabbitMQ: Denial of Service via unbounded consistent-hash exchange weight CVE-2026-67220 — rabbitmq-server: RabbitMQ: Denial of Service via JMS topic exchange atom exhaustion CVE-2026-67221 — rabbitmq: RabbitMQ: Information disclosure of AMQP 1.0 shovel URI passwords CVE-2026-67224 — rabbitmq: RabbitMQ: Administrator path traversal allows arbitrary file write CVE-2026-67228 — rabbitmq: RabbitMQ: Denial of Service via atom exhaustion in runtime-parameter component CVE-2026-67229 — RabbitMQ: RabbitMQ: Denial of Service via admin-only atom exhaustion from crafted vhost metadata CVE-2026-67232 — rabbitmq: rabbitmq_web_mqtt: RabbitMQ Web-MQTT plugin: Denial of Service via decompression bomb CVE-2026-67233 — rabbitmq-server: RabbitMQ: Privilege escalation allows monitoring users to delete shovels CVE-2026-67235 — rabbitmq-server: RabbitMQ: Denial of Service via AMQP 0-9-1 body size validation bypass CVE-2026-67238 — rabbitmq-server: RabbitMQ: Denial of Service due to atom-table exhaustion via reply-to queue name decoding CVE-2026-67240 — RabbitMQ: RabbitMQ: Denial of Service via crafted AMQP 1.0 SQL LIKE filter CVE-2026-67241 — rabbitmq-server: rabbitmq-server: Unauthorized message routing via missing alternate-exchange permission check CVE-2026-67242 — rabbitmq-server: rabbitmq-server: Authentication bypass via improper validation of floating-point token expiration timestamps CVE-2026-67405 — rabbitmq-server: RabbitMQ: Cross-Site WebSocket Hijacking via missing Origin header validation CVE-2026-67412 — rabbitmq-server: RabbitMQ: Unauthorized cross-vhost message access via missing Federation upstream authorization CVE-2026-67420 — rabbitmq-server: rabbitmq-server: Unauthorized user impersonation via stale OAuth token refresh

🎯 Affected products4

  • Red Hat Hardened Images
  • rabbitmq-server4.3-0:4.3.6-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • rabbitmq-server4.3-0:4.3.6-1.hum1@src as a component of Red Hat Hardened Images
  • rabbitmq-server4.3-0:4.3.6-1.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate this issue, restrict access to the RabbitMQ management UI to trusted administrators only. Ensure that administrative interfaces are not exposed to untrusted networks. Workaround: Restrict Management API access and monitoring-tag accounts, or disable the Management plugin where it is not needed. Workaround: Replace wildcard CORS with explicit trusted origins and avoid administrator Basic credentials in browsers used for untrusted sites. Workaround: Disable the stream plugin if unused, and restrict stream access to trusted clients. Workaround: Restrict monitoring access and disable federation management where it is not needed. Workaround: Restrict untrusted network access to AMQP listeners; disable AMQP 1.0 support if unused. Workaround: Restrict management-tagged accounts and disable stream management where it is not needed. Workaround: Restrict that access or disable stream management where it is not needed. Workaround: Disable the JMS topic exchange plugin if unused and restrict binding permissions to trusted users. Workaround: Disable the shovel management extension on brokers that do not need to manage shovels over HTTP. Enable rabbitmq_shovel explicitly first so it stays active if it was only pulled in as a dependency: rabbitmq-plugins enable rabbitmq_shovel rabbitmq-plugins disable rabbitmq_shovel_management This removes the /api/shovels endpoint. Accounts with the policymaker or administrator tag can still delete shovels through /api/parameters, which enforces the correct role check. If the endpoint has to stay available, remove the monitoring tag from any account that should not be able to stop message flow. Workaround: Restrict publish access to trusted clients; broker memory alarms offer only partial protection until an updated build is deployed. Workaround: Restrict AMQP access to trusted clients until an updated build is deployed. Workaround: Disable Web-STOMP and Web-MQTT where unnecessary, or avoid those non-default authentication options until an updated build is deployed.

🔗 References (58)