Sensitive Credential Exposure in RabbitMQ Messaging and Streaming Broker
CVE-2026-67221

5.9MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
23 September 2026

What is CVE-2026-67221?

A vulnerability in RabbitMQ's AMQP 1.0 shovel can expose sensitive connection credentials. The AMQP 1.0 shovel mistakenly stores the raw connection URI, including the password, making it accessible via the API and through rabbitmqctl commands. This occurs when the Shovel plugin is configured to use URI-embedded credentials. Versions prior to 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 are impacted, and users are advised to update to secure versions promptly to mitigate the risk of credential exposure.

Affected Version(s)

rabbitmq-server >= 3.13.0, < 3.13.15 < 3.13.0, 3.13.15

rabbitmq-server >= 4.0.0, < 4.0.20 < 4.0.0, 4.0.20

rabbitmq-server >= 4.1.0, < 4.1.11 < 4.1.0, 4.1.11

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.