PatchSiren cyber security CVE debrief
CVE-2026-106123 RabbitMQ CVE debrief
CVE-2026-106123: The RabbitMQ Java client library contains a vulnerability where plaintext broker credentials are leaked in exception messages during property-file/Map-based ConnectionFactory setup. This occurs when parsing the 'uri' key fails, causing the raw connection string, including the username and password, to be concatenated into the exception message. The affected code is located in ConnectionFactoryConfigurator.load(). Defenders should prioritize verifying and remediating affected RabbitMQ Java client versions, focusing on configurations where credentials are dynamically set or logged. The remediation involves updating to version 5.35.0 or later. This vulnerability poses
- Vendor
- RabbitMQ
- Product
- RabbitMQ Java client (amqp-client)
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for RabbitMQ Java client configurations, developers using the library, and security teams monitoring for potential credential leaks should assess exposure and prioritize remediation.
Why it matters
CVE-2026-106123 RabbitMQ Java client leaks plaintext broker credentials in exception messages, posing a risk of credential exposure and compromise. Defenders should verify and remediate affected versions, focusing on configurations where credentials are dynamically set or logged.
- Potential exposure of sensitive credentials in logs or exception messages
- Increased risk of credential compromise or unauthorized access
- Need for verification of affected versions and configurations in use
- Priority for updating to remediated version 5.35.0 or later
Technical summary
The RabbitMQ Java client library leaks plaintext broker credentials in exception messages when property-file/Map-based ConnectionFactory setup fails while parsing the uri key. This occurs in ConnectionFactoryConfigurator.load(), where the raw connection string including username and password is concatenated into the exception message on URISyntaxException, NoSuchAlgorithmException, or KeyManagementException catch branches.
Defensive priority
Defenders should prioritize verifying and remediating affected RabbitMQ Java client versions, focusing on configurations where credentials are dynamically set or logged.
Recommended defensive actions
- Verify and inventory affected RabbitMQ Java client versions in use
- Review configurations where credentials are dynamically set or logged
- Remediate by updating to version 5.35.0 or later
- Monitor exception messages for potential credential leaks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The RabbitMQ Java client library leaks plaintext broker credentials in exception messages when property-file/Map-based ConnectionFactory setup fails while parsing the uri key. This occurs in ConnectionFactoryConfigurator.load().
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106123 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106123
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106123 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106123
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFa
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/Maven/GHSA-h6w7-qmcm-q6xr.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-h6w7-qmcm-q6xr
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/pull/2052
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/commit/daca1875cdb8b8c0acce78f71103b21a05478446
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.35.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.