Automatic Credential Exposure in RabbitMQ Shovel Worker
CVE-2026-67406

4.6MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
25 September 2026

What is CVE-2026-67406?

A flaw in RabbitMQ's Shovel worker allows plaintext credentials, including AMQP passwords and URIs, to be logged in error reports. This occurs when the worker crashes, such as during network interruptions, causing sensitive information to be written to the logs without proper formatting. The vulnerability is prevalent across multiple RabbitMQ versions and can lead to unauthorized access to messaging systems if exploited. The affected versions from 4.0.0 to 4.3.2, including specified patch versions, can be secured by upgrading to the latest releases, where this issue has been addressed.

Affected Version(s)

rabbitmq-server >= 4.3.0, < 4.3.3 < 4.3.0, 4.3.3

rabbitmq-server >= 4.2.0, < 4.2.9 < 4.2.0, 4.2.9

rabbitmq-server >= 4.1.0, < 4.1.14 < 4.1.0, 4.1.14

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.