AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106123.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.7CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary When property-file/Map-based `ConnectionFactory` setup fails while parsing the `uri` key, the library wraps the underlying exception with the raw connection string — including the plaintext username and password — baked verbatim into the new exception's message. ### Details `ConnectionFactoryConfigurator.load(ConnectionFactory, Map, String)` (`src/main/java/com/rabbitmq/client/ConnectionFactoryConfigurator.java`, lines 142-155): String uri = properties.get(prefix + "uri"); if (uri != null) { try { cf.setUri(uri); } catch (URISyntaxException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } catch (NoSuchAlgorithmException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } catch (KeyManagementException e) { throw new IllegalArgumentException("Error while setting AMQP URI: " + uri, e); } } `uri` is the full AMQP URI — `amqp(s)://username:password@host:port/vhost` — concatenated verbatim into the exception message on any of the three catch branches. No masking/redaction exists anywhere in this class or in `ConnectionFactory.setUri()`. This is the library's documented Spring-Boot/ops-config entry point (`

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-h6w7-qmcm-q6xr

Open original source · Updated Oct 07, 2026

RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()

Source severity: MEDIUM / 5.7

EcosystemPackageAffected rangeFirst patched
mavencom.rabbitmq:amqp-client5.35.0

Original records & references

PUBLISHED 2026-10-07T12:19:22-04:00
MODIFIED 2026-10-07T12:19:23-04:00
INGESTED 2026-10-08T12:05:11-04:00