Information disclosure in RabbitMQ Server - #VU139294
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in rabbit_shovel_worker when crash reports or crash dumps are generated after shovel worker process failures. A remote privileged user can trigger shovel worker failures and access logged state data to disclose sensitive information.
Plaintext AMQP credentials and URIs stored in the shovel worker process state may be written to SASL error logs and Erlang crash dumps. Network partitions or connection failures can trigger the affected crash reporting path.