Automatic Credential Exposure in RabbitMQ Shovel Worker
CVE-2026-67406
4.6MEDIUM
What is CVE-2026-67406?
A flaw in RabbitMQ's Shovel worker allows plaintext credentials, including AMQP passwords and URIs, to be logged in error reports. This occurs when the worker crashes, such as during network interruptions, causing sensitive information to be written to the logs without proper formatting. The vulnerability is prevalent across multiple RabbitMQ versions and can lead to unauthorized access to messaging systems if exploited. The affected versions from 4.0.0 to 4.3.2, including specified patch versions, can be secured by upgrading to the latest releases, where this issue has been addressed.
Affected Version(s)
rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3
rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9
rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14
