RabbitMQ Java Client, Plaintext Credential Information Disclosure, CVE-2026-106123 (Medium) -DC-Oct2026-2819

Listen to this Post

When property-file or Map-based `ConnectionFactory` setup fails while parsing the `uri` key, the library wraps the underlying exception with the raw connection string baked verbatim into the new exception’s message.
The issue resides in `ConnectionFactoryConfigurator.load(ConnectionFactory, Map, String)` at src/main/java/com/rabbitmq/client/ConnectionFactoryConfigurator.java.
When `properties.get(prefix + “uri”)` fetches an AMQP URI string formatted as amqp(s)://username:password@host:port/vhost, it passes this string to cf.setUri(uri).
If `setUri` fails, three distinct catch blocks wrap the underlying failure inside a new IllegalArgumentException("Error while setting AMQP URI: " + uri, e).
This raw concatenation includes the plaintext username and password without any sanitization, masking, or redaction.
Because `ConnectionFactoryConfigurator.load(…)` is the primary entry point for Spring Boot and ops-config initializations, this flaw directly affects standard setup paths.
RabbitMQ’s official AMQP URI specification explicitly prohibits embedding credentials in exception logs or debug messages.
While sibling methods such as `ConnectionFactory.setUri(URI)` properly sanitize input during parsing errors, `ConnectionFactoryConfigurator.load()` failed to implement this safeguard.
Out of the three caught exceptions, `KeyManagementException` is currently unreachable via setUri(String).
The primary reachable leak surfaces are `URISyntaxException` and NoSuchAlgorithmException.
`URISyntaxException` triggers deterministically whenever the URI contains common reserved characters like spaces in passwords.
`NoSuchAlgorithmException` triggers on restricted FIPS or TLS-customized providers under `amqps://` schemes.
When any parsing error occurs, default application loggers capture the exception and print the unredacted string.
The underlying `URISyntaxException` itself also retains the raw input string within its chained cause message.
As a result, stripping the string concatenation in the wrapper alone is insufficient; raw userinfo must be omitted entirely from parsing error paths.
This design leads to widespread credential exposure across application performance monitoring systems, CI logs, and crash reports.

DailyCVE Form:

Platform: RabbitMQ Java Client
Version: Prior to 5.35.0
Vulnerability: Credential Information Disclosure
Severity: Medium
date: October 06 2026

Prediction: Already Fixed 5.35.0

What Undercode Say: Analytics

Analytics

The root cause lies in improper exception handling where sensitive userinfo parameters are concatenated into error messages before redacting plaintext credentials. When applications boot up using standard Spring Boot configuration properties, any syntax failure in the AMQP URI string triggers an `IllegalArgumentException` carrying the full secret.

Environment setup to inspect application logs during Spring Boot startup failure
Search for leaked plaintext broker credentials in application and system logs
grep -E "Error while setting AMQP URI: amqp" /var/log/app/application.log
grep -rn "amqp://" /var/log/containers/
package com.example.vulnerability;
import com.rabbitmq.client.ConnectionFactory;
import com.rabbitmq.client.ConnectionFactoryConfigurator;
import java.util.HashMap;
import java.util.Map;
public class CredentialLeakPoC {
public static void main(String[] args) {
// Map payload containing a password with a space character causing URISyntaxException
Map<String, String> props = new HashMap<>();
props.put("uri", "amqp://svc-account:P@ssW0rd With [email protected]:5672/prod");
ConnectionFactory cf = new ConnectionFactory();
try {
// Documented entry point for property/map based initialization
ConnectionFactoryConfigurator.load(cf, props, "");
} catch (IllegalArgumentException e) {
// Prints raw exception containing unredacted plaintext credentials
System.err.println("Caught Expected Exception:");
e.printStackTrace();
}
}
}

How Exploit: (Educational Purposes!)

  1. An attacker or unauthorized user inspects centralized log storage, CI/CD build outputs, APM traces, or issue tracker tickets.
  2. The application is supplied with an AMQP URI property that contains special characters (e.g., spaces in the password) or an invalid host/scheme structure.

3. During application startup, `ConnectionFactoryConfigurator.load()` executes `cf.setUri(uri)`.

4. `java.net.URI` fails to parse the string and throws a URISyntaxException.
5. `ConnectionFactoryConfigurator` catches the exception and re-throws a wrapped IllegalArgumentException("Error while setting AMQP URI: " + uri, e).
6. The application logging framework captures the stack trace and writes the full connection string containing the plaintext username and password to log files or monitoring services.
7. The attacker reads the exposed plaintext credentials from the log stream and gains unauthorized access to the target RabbitMQ broker.

Protection:

  1. Upgrade Library: Update `rabbitmq-java-client` to version `5.35.0` or later where raw URI formatting is redacted from exception messages.
  2. Sanitize Configuration: Ensure connection strings passed to property maps URL-encode special characters in passwords before application initialization.
  3. Log Sanitization: Implement log masking rules in logging utilities (e.g., Logback, Log4j2) to automatically redact patterns matching amqp(s)://:@.
  4. Access Control: Restrict read permissions on build logs, container stdout, and APM platforms containing application startup logs.

Impact:

Exposure of plaintext RabbitMQ broker credentials (username and password) to application startup logs, APM systems, CI build logs, and stack traces. Attackers with access to log infrastructure can extract these secrets and compromise the messaging queue infrastructure.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top