Insufficiently protected credentials in RabbitMQ Server - #VU143929
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive credentials.
The vulnerability exists due to insufficiently protected credentials in the shovel management HTTP API endpoint GET /api/shovels/vhost/{vhost}/{name} when returning stored dynamic shovel definitions. A remote user can send a request to the per-shovel management endpoint to disclose sensitive credentials.
Only instances with rabbitmq_shovel and rabbitmq_shovel_management enabled are vulnerable. The issue affects dynamic shovels whose URIs embed credentials and that are in a reporting state so they appear in shovel status.