PT-2026-46260 · Openstack+1 · Oslo.Messaging+1

·

CVE-2026-44393

·

Published

2026-06-04

·

Updated

2026-07-23

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions oslo.messaging versions 1.0.0 through 17.3.0
Description The RabbitMQ driver in oslo.messaging fails to perform TLS hostname verification when connecting to the message broker. While the driver enables certificate chain validation when ssl ca file is configured, it does not pass the expected broker hostname to the TLS stack. Consequently, any certificate signed by the deployment CA is accepted regardless of the hostname. This allows an attacker capable of intercepting control-plane traffic to impersonate the RabbitMQ broker and execute a man-in-the-middle attack on RPC and notification traffic. All OpenStack services utilizing oslo.messaging with RabbitMQ over TLS are impacted.
Recommendations Update to version 18.1.0-1.1 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44393
GHSA-76QH-XR7Q-H39M
OPENSUSE-SU-2026:10973-1
PYSEC-2026-3492

Affected Products

Rabbitmq
Oslo.Messaging