Cleartext Password Exposure in RabbitMQ Management Aliveness Check by Spring Framework
CVE-2026-59271
5.3MEDIUM
What is CVE-2026-59271?
A vulnerability exists in the RabbitMQ management feature where if the management aliveness check fails, the configured administrator password is exposed in cleartext within the thrown exception message. This can lead to unauthorized access if the exception details are logged or intercepted. It affects multiple versions of Spring AMQP, specifically versions 4.1.0 and prior. Proper precautions should be taken to handle exception messages securely to mitigate the risk of credential exposure.
Affected Version(s)
Spring AMQP 4.1.0
Spring AMQP 4.0.0 <= 4.0.4
Spring AMQP 3.2.0 <= 3.2.12
