{"id":"CVE-2026-67221","published":"2026-09-23T21:17:00.363","lastModified":"2026-09-24T15:02:58.307","description":"RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel_status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-312"],"vendors":[],"products":[],"references":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x5h5-588r-cv55","tags":[]}],"exploitRefs":[{"url":"https://github.com/rabbitmq/rabbitmq-server/releases/tag/v4.2.6","tags":[]},{"url":"https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x5h5-588r-cv55","tags":[]}],"hasPoc":true,"ai":null}