CVE-2026-66070 | RabbitMQ up to 3.13.16/4.0.21/4.1.12/4.2.5 CORS rabbit_mgmt_cors.erl match_origin cross-domain policy

SecurityVulns

A vulnerability, which was classified as problematic, has been found in RabbitMQ up to 3.13.16/4.0.21/4.1.12/4.2.5. The impacted element is the function match_origin of the file rabbit_mgmt_cors.erl of the component CORS Handler. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is tracked as CVE-2026-66070. The attack is possible to be carried out remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More