CVE-2026-44393

EUVD-2026-34294
An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expected broker hostname into the underlying TLS stack. Any certificate signed by the deployment CA is accepted regardless of hostname, allowing an attacker who can intercept control-plane traffic to impersonate the RabbitMQ broker and perform a man-in-the-middle attack on RPC and notification traffic. All OpenStack services using oslo.messaging with RabbitMQ over TLS are affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6.75%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat OpenStack Platform 16.2
0:10.2.4-2.20260710155333.82281a0.el8ost ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-oslo.messaging
bookworm
14.0.3-0+deb12u1
fixed
bookworm (security)
14.0.3-0+deb12u1
fixed
forky
17.3.0-4
fixed
sid
17.3.0-4
fixed
trixie
16.1.0-3+deb13u1
fixed
trixie (security)
16.1.0-3+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-oslo.messaging
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage