CVE-2026-67221: CWE-312: Cleartext Storage of Sensitive Information in rabbitmq rabbitmq-server
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel_status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
AI Analysis
Technical Summary
RabbitMQ versions prior to 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 contain a cleartext storage vulnerability (CWE-312) in the AMQP 1.0 shovel feature. Unlike the AMQP 0-9-1 shovel which removes credentials before storing the connection URI, the AMQP 1.0 shovel stores the full URI including the password. This sensitive information is exposed via the GET /api/shovels endpoint and the rabbitmqctl shovel_status command. Exploitation requires the Shovel plugin enabled with AMQP 1.0 shovels configured using URI-embedded credentials and monitoring privileges to read the exposed status. The issue is resolved in the fixed versions listed.
Potential Impact
Sensitive credentials embedded in the AMQP 1.0 shovel connection URI are stored in cleartext and exposed through API and command-line interfaces. This could lead to credential disclosure to users with monitoring access, potentially allowing unauthorized access to messaging resources if monitoring permissions are improperly assigned.
Mitigation Recommendations
Upgrade rabbitmq-server to one of the fixed versions: 3.13.15, 4.0.20, 4.1.11, 4.2.6, or 4.3.0. This update removes credentials from the stored URI in the AMQP 1.0 shovel. Until upgraded, avoid using URI-embedded credentials with AMQP 1.0 shovels or restrict monitoring access to trusted users only.
CVE-2026-67221: CWE-312: Cleartext Storage of Sensitive Information in rabbitmq rabbitmq-server
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel_status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
CVSS v4.0
Score 5.9medium
Affected software
rabbitmq
rabbitmq-server
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RabbitMQ versions prior to 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0 contain a cleartext storage vulnerability (CWE-312) in the AMQP 1.0 shovel feature. Unlike the AMQP 0-9-1 shovel which removes credentials before storing the connection URI, the AMQP 1.0 shovel stores the full URI including the password. This sensitive information is exposed via the GET /api/shovels endpoint and the rabbitmqctl shovel_status command. Exploitation requires the Shovel plugin enabled with AMQP 1.0 shovels configured using URI-embedded credentials and monitoring privileges to read the exposed status. The issue is resolved in the fixed versions listed.
Potential Impact
Sensitive credentials embedded in the AMQP 1.0 shovel connection URI are stored in cleartext and exposed through API and command-line interfaces. This could lead to credential disclosure to users with monitoring access, potentially allowing unauthorized access to messaging resources if monitoring permissions are improperly assigned.
Mitigation Recommendations
Upgrade rabbitmq-server to one of the fixed versions: 3.13.15, 4.0.20, 4.1.11, 4.2.6, or 4.3.0. This update removes credentials from the stored URI in the AMQP 1.0 shovel. Until upgraded, avoid using URI-embedded credentials with AMQP 1.0 shovels or restrict monitoring access to trusted users only.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-28T19:50:39.437Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab43e93f7a7c54106550f89
Added to database: 09/23/2026, 21:03:15 UTC
Last enriched: 09/23/2026, 21:18:21 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.