Information disclosure in RabbitMQ Server - #VU139294

 

Information disclosure in RabbitMQ Server - #VU139294

Published: July 24, 2026


Vulnerability identifier: #VU139294
CSH Severity: Low
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in rabbit_shovel_worker when crash reports or crash dumps are generated after shovel worker process failures. A remote privileged user can trigger shovel worker failures and access logged state data to disclose sensitive information.

Plaintext AMQP credentials and URIs stored in the shovel worker process state may be written to SASL error logs and Erlang crash dumps. Network partitions or connection failures can trigger the affected crash reporting path.


Affected software

RabbitMQ Server

Remediation

Install security update from vendor's website.

RabbitMQ Server - addressed in versions 4.0.23, 4.1.14, 4.2.9, 4.3.3

External References

Related Security Bulletins