Medium severityNVD Advisory· Published Sep 23, 2026
CVE-2026-67221
CVE-2026-67221
Description
RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel_status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.
Affected products
1- Range: <3.13.15, <4.0.20, <4.1.11, <4.2.6, <4.3.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.