PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106123 RabbitMQ CVE debrief

CVE-2026-106123: The RabbitMQ Java client library contains a vulnerability where plaintext broker credentials are leaked in exception messages during property-file/Map-based ConnectionFactory setup. This occurs when parsing the 'uri' key fails, causing the raw connection string, including the username and password, to be concatenated into the exception message. The affected code is located in ConnectionFactoryConfigurator.load(). Defenders should prioritize verifying and remediating affected RabbitMQ Java client versions, focusing on configurations where credentials are dynamically set or logged. The remediation involves updating to version 5.35.0 or later. This vulnerability poses

Vendor
RabbitMQ
Product
RabbitMQ Java client (amqp-client)
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for RabbitMQ Java client configurations, developers using the library, and security teams monitoring for potential credential leaks should assess exposure and prioritize remediation.

Why it matters

CVE-2026-106123 RabbitMQ Java client leaks plaintext broker credentials in exception messages, posing a risk of credential exposure and compromise. Defenders should verify and remediate affected versions, focusing on configurations where credentials are dynamically set or logged.

  • Potential exposure of sensitive credentials in logs or exception messages
  • Increased risk of credential compromise or unauthorized access
  • Need for verification of affected versions and configurations in use
  • Priority for updating to remediated version 5.35.0 or later

Technical summary

The RabbitMQ Java client library leaks plaintext broker credentials in exception messages when property-file/Map-based ConnectionFactory setup fails while parsing the uri key. This occurs in ConnectionFactoryConfigurator.load(), where the raw connection string including username and password is concatenated into the exception message on URISyntaxException, NoSuchAlgorithmException, or KeyManagementException catch branches.

Defensive priority

Defenders should prioritize verifying and remediating affected RabbitMQ Java client versions, focusing on configurations where credentials are dynamically set or logged.

Recommended defensive actions

  • Verify and inventory affected RabbitMQ Java client versions in use
  • Review configurations where credentials are dynamically set or logged
  • Remediate by updating to version 5.35.0 or later
  • Monitor exception messages for potential credential leaks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The RabbitMQ Java client library leaks plaintext broker credentials in exception messages when property-file/Map-based ConnectionFactory setup fails while parsing the uri key. This occurs in ConnectionFactoryConfigurator.load().

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106123 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106123

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106123 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106123

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFa

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/Maven/GHSA-h6w7-qmcm-q6xr.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-h6w7-qmcm-q6xr

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/pull/2052

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/commit/daca1875cdb8b8c0acce78f71103b21a05478446

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.35.0

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.