Cleartext transmission of sensitive information in RabbitMQ Java Client Library - #VU137273

 

Cleartext transmission of sensitive information in RabbitMQ Java Client Library - #VU137273

Published: July 9, 2026


Vulnerability identifier: #VU137273
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-319
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to cleartext transmission of credentials in the default connection configuration when using the default plaintext port with PLAIN SASL. A remote attacker can observe network traffic to disclose sensitive information.

The default port is 5672, and credentials may be sent unencrypted in this configuration.


Affected software

RabbitMQ Java Client Library

Remediation

Install security update from vendor's website.

RabbitMQ Java Client Library - update to 5.33.0

External References

Related Security Bulletins