Cross-site scripting in RabbitMQ Server - #VU139288
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in the operator's browser.
The vulnerability exists due to cross-site scripting in the stream-connection detail page template when rendering TLS peer-certificate distinguished name fields. A remote attacker can present a certificate with a crafted distinguished name to execute arbitrary script code in the operator's browser.
User interaction is required because an operator must open the stream-connection detail page, and exploitation requires a stream TLS listener configured with peer verification and a trusted certificate containing an attacker-controlled distinguished name.