Information disclosure in RabbitMQ Server - #VU139295
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in the unauthenticated /js/oidc-oauth/bootstrap.js endpoint when serving JavaScript bootstrap content for the management UI. A remote attacker can send a crafted request to retrieve the OAuth2 client secret and disclose sensitive information.
Only deployments with the management UI enabled, OAuth2 authentication enabled, and a configured oauth_client_secret are vulnerable.