CVE-2026-67234

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary/1 on the strict_auth_mechanism or preferred_auth_mechanism atom when clearing the corresponding cookie, producing a non-ASCII cookie name that violates RFC 6265 and can prevent the browser from deleting the preference. The issue is not directly exploitable for code execution or data exfiltration; its security relevance is limited to stale authentication-mechanism preferences persisting across logout and login cycles. This issue is fixed in versions 4.2.8 and 4.3.2.

  • Published Sep 25, 2026
  • CVSS 2.3 low
  • 0.6% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-67234 at the National Vulnerability Database