Credentials Exposure in RabbitMQ Java Client Library
CVE-2026-106123

5.7MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106123?

The RabbitMQ Java Client Library, a critical component for Java and JVM-based applications, has a vulnerability that exposes broker credentials due to mishandling of AMQP URIs in error logs. In versions prior to 5.35.0, the raw URI value is included in exceptions when URI parsing fails, potentially revealing sensitive information such as plaintext usernames and passwords in startup logs, application monitoring systems, and copied stack traces. This issue poses a risk of unauthorized access to RabbitMQ brokers by exposing credentials to unintended users. Version 5.35.0 addresses this problem effectively.

Affected Version(s)

amqp-client < 5.35.0

rabbitmq-java-client < 5.35.0

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.