Disclosure summary
### Summary When property-file/Map-based `ConnectionFactory` setup fails while parsing the `uri` key, the library wraps the underlying exception with the raw connection string — including the plaintext username and password — baked verbatim into the new exception's message. ### Details `ConnectionFactoryConfigurator.load(ConnectionFactory, Map, String)` (`src/main/java/com/rabbitmq/client/ConnectionFactoryConfigurator.java`, lines 142-155): String uri = properties.get(prefix + "uri"); if (uri != null) { try { cf.setUri(uri); } catch (URISyntaxException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } catch (NoSuchAlgorithmException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } catch (KeyManagementException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } } `uri` is the full AMQP URI — `amqp(s)://username:password@host:port/vhost` — concatenated verbatim into the exception message on any of the three catch branches. No masking/redaction exists anywhere in this class or in `ConnectionFactory.setUri()`. This is the library's documented Spring-Boot/ops-config entry point (`
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-h6w7-qmcm-q6xr
Open original source · Updated Oct 07, 2026
RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()
Source severity: MEDIUM / 5.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | com.rabbitmq:amqp-client | 5.35.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:19:22-04:00
MODIFIED 2026-10-07T12:19:23-04:00
INGESTED 2026-10-08T12:05:11-04:00