Cleartext Password Exposure in RabbitMQ Management Aliveness Check by Spring Framework
CVE-2026-59271

5.3MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59271?

A vulnerability exists in the RabbitMQ management feature where if the management aliveness check fails, the configured administrator password is exposed in cleartext within the thrown exception message. This can lead to unauthorized access if the exception details are logged or intercepted. It affects multiple versions of Spring AMQP, specifically versions 4.1.0 and prior. Proper precautions should be taken to handle exception messages securely to mitigate the risk of credential exposure.

Affected Version(s)

Spring AMQP 4.1.0

Spring AMQP 4.0.0 <= 4.0.4

Spring AMQP 3.2.0 <= 3.2.12

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.