Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection.openComplete method in connection.go does not clear those values. Code with access to the Connection object, including reflective loggers, application performance monitoring agents, debugging utilities, and panic handlers, can traverse the configuration and expose the credentials to logs or state captures. The credential remains available for the lifetime of the connection instead of being cleared after authentication. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Plaintext credential exposure
Action: Patch now
AI Analysis

Impact

The amqp091-go client retains the plain text password in exported fields of the PlainAuth struct after a successful PLAIN authentication handshake. This means that any code with access to the Connection.Config.SASL object—such as reflective loggers, monitoring agents, debugging utilities, or panic handlers—can read and potentially log the credentials. The flaw is a classic example of insecure storage of sensitive data, classified as CWE-316, and allows an attacker with code execution or log access to capture valid RabbitMQ credentials, potentially leading to unauthorized broker access or lateral movement.

Affected Systems

All deployments using rabbitmq:amqp091-go older than version 1.13.0 are affected. The issue is present in any build that has not been updated to the patched release.

Risk and Exploitability

The CVSS score of 7 indicates high severity, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. Because the vulnerability requires access to the application’s process or its logs, the attack vector is likely local or requires a compromised application. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed widespread exploits yet.

Generated by OpenCVE AI on September 18, 2026 at 02:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the amqp091-go client to version 1.13.0 or later to eliminate plaintext password storage.
  • Remove or sanitize any logging, monitoring or debugging code that accesses or serializes Connection.Config.SASL, ensuring sensitive fields are omitted.
  • Restrict process privileges and isolate application components so that only trusted code can access connection objects, narrowing the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-27gv-rfvv-22mv RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-256
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 16 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection.openComplete method in connection.go does not clear those values. Code with access to the Connection object, including reflective loggers, application performance monitoring agents, debugging utilities, and panic handlers, can traverse the configuration and expose the credentials to logs or state captures. The credential remains available for the lifetime of the connection instead of being cleared after authentication. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authentication Struct Fields
Weaknesses CWE-316
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:L/SA:L'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T14:59:54.889Z

Reserved: 2026-08-20T19:55:27.023Z

Link: CVE-2026-77407

cve-icon Vulnrichment

Updated: 2026-09-16T14:59:51.337Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:49.210

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-77407

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T14:34:18Z

Links: CVE-2026-77407 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-256

    Plaintext Storage of a Password

  • CWE-316

    Cleartext Storage of Sensitive Information in Memory