Go AMQP Client Vulnerability in RabbitMQ Product
CVE-2026-77407

7HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
16 September 2026

What is CVE-2026-77407?

The RabbitMQ amqp091-go client, prior to version 1.13.0, contains a vulnerability where passwords used during PlainAuth are retained as plaintext in the connection configuration after authentication. This occurs because the Connection.openComplete method fails to erase sensitive data, leading to potential exposure of credentials through various logging and monitoring tools. As a result, any application or utility with access to the Connection object can inadvertently log or capture these credentials, posing a security risk. The issue has been addressed in version 1.13.0.

Affected Version(s)

amqp091-go < 1.13.0

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.