PT-2026-106844 · Vmware · Rabbitmq Java Client
CVE-2026-106123
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v4.0
5.7
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RabbitMQ Java client library versions prior to 5.35.0
Description
The
ConnectionFactoryConfigurator.load() function includes the raw URI value in wrapped exceptions when AMQP URI parsing fails. Since the URI can contain plaintext usernames and passwords, sensitive broker credentials may be disclosed in startup logs, application performance monitoring systems, CI logs, and stack traces.Recommendations
Update to version 5.35.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rabbitmq Java Client