CVE-2026-67236 | RabbitMQ up to 4.2.7/4.3.1 Login is_authorized cookie httponly flag
A vulnerability classified as problematic was found in RabbitMQ up to 4.2.7/4.3.1. The impacted element is the function is_authorized of the component Login. The manipulation results in cookie without ‘httponly’ flag.
This vulnerability is known as CVE-2026-67236. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More