Description
The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password, startup logs, application performance monitoring systems, CI logs, and copied stack traces can disclose broker credentials to users who should not have access to them. This issue is fixed in version 5.35.0.
Published: 2026-10-06
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: Credential Exposure via Exception Messages
Action: Update Library
AI Analysis

Impact

The RabbitMQ Java client library allows Java and JVM-based applications to connect to RabbitMQ nodes. Prior to version 5.35.0, the ConnectionFactoryConfigurator.load() method embeds the raw AMQP URI in wrapped exceptions when parsing fails. This URI may include a plaintext username and password, so the exception message can leak broker credentials to anyone who can view logs, startup output, or stack traces. The defect is classified as insecure private data exposure (CWE-509) and results in credential disclosure rather than a code‑execution flaw.

Affected Systems

Affected products are the RabbitMQ Java client libraries identified by com.rabbitmq:amqp-client and rabbitmq:rabbitmq-java-client. Any deployment that includes a version older than 5.35.0 was vulnerable. The issue was fixed in version 5.35.0 and later releases.

Risk and Exploitability

The CVSS score of 5.7 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers are most likely to exploit this weakness when application logs or error output are accessible to unauthorized parties, which may happen in shared hosting environments, CI systems, or when stack traces are copied to unprotected locations. The flaw does not enable remote code execution, but it can compromise account access by revealing sensitive credentials that are otherwise protected.

Generated by OpenCVE AI on October 6, 2026 at 19:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the RabbitMQ Java client library to version 5.35.0 or later to remove the URI leakage bug.
  • If an immediate upgrade is not feasible, rewrite any AMQP URI configuration to exclude the username and password before passing it to the library, or encrypt the credentials and populate them after a safe connection is established.
  • Audit existing application logs and monitoring systems to ensure that exception messages or stack traces do not contain sensitive information, and configure the logging framework to filter or redact such data.

Generated by OpenCVE AI on October 6, 2026 at 19:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.35.0, ConnectionFactoryConfigurator.load() includes the raw uri value in wrapped exceptions when AMQP URI parsing fails. Because the URI may contain a plaintext username and password, startup logs, application performance monitoring systems, CI logs, and copied stack traces can disclose broker credentials to users who should not have access to them. This issue is fixed in version 5.35.0.
Title RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()
Weaknesses CWE-509
References
Metrics cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:29:27.567Z

Reserved: 2026-10-06T15:33:55.334Z

Link: CVE-2026-106123

cve-icon Vulnrichment

Updated: 2026-10-06T19:25:54.166Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:43.647

Modified: 2026-10-06T20:17:17.930

Link: CVE-2026-106123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T19:45:04Z

Weaknesses
  • CWE-509

    Replicating Malicious Code (Virus or Worm)