CVE-2026-59271

Summary

When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

Affected Software

VendorProductVersion RangeStatus
SpringSpring AMQP4.1.0affected
SpringSpring AMQP4.0.0 <= 4.0.4affected
SpringSpring AMQP3.2.0 <= 3.2.12affected
SpringSpring AMQP0 <= 2.4.18affected

Weaknesses

  • CWE-209 Generation of Error Message Containing Sensitive Information

References