CVE WATCH / VULNERABILITY DETAIL

CVE-2026-66070

UNKNOWNCVSS 0NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Cred

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-66070 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-66070

UNKNOWNCVSS 0NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoed the attacker's origin together with Access-Control-Allow-Cred

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]