Inclusion of Sensitive Information in Log Files in Spring AMQP - CVE-2026-59271

 

Inclusion of Sensitive Information in Log Files in Spring AMQP - CVE-2026-59271

Published: August 28, 2026


Vulnerability identifier: #VU146203
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59271
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to insertion of sensitive information into log or exception messages in the BrokerNotAliveException message when the RabbitMQ management aliveness check fails. A remote user can trigger the check failure to disclose sensitive information.

This occurs when a real credential is supplied through RABBITMQ_TEST_ADMIN_PASSWORD and test output or CI logs are accessible for reading.


Affected software

Spring AMQP

How to mitigate CVE-2026-59271

Install security update from vendor's website.

Spring AMQP - addressed in versions 2.4.19, 3.2.13, 4.0.4.1, 4.0.5, 4.1.0.1, 4.1.1

External References

Related Security Bulletins