RabbitMQ Java 客户端库允许 Java 和基于 JVM 的应用程序连接并与 RabbitMQ 节点进行交互。在 5.35.0 版本之前,当 AMQP URI 解析失败时, 方法会在包装后的异常中包含原始的 URI 值。由于 URI 中可能包含明文的用户名和密码,启动日志、应用性能监控系统(APM)、持续集成(CI)日志以及复制的堆栈跟踪信息都可能将代理(broker)的凭据泄露给不应访问这些凭据的用户。该问题已在 5.35.0 版本中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| com.rabbitmq | amqp-client | < 5.35.0 |
affected |
| rabbitmq | rabbitmq-java-client | < 5.35.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| rabbitmq | rabbitmq-java-client | < 5.35.0 | - |
|
| com.rabbitmq | amqp-client | < 5.35.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106122 | 6.0 MEDIUM | RabbitMQ: Malformed UTF-8 in shortstr properties permanently disables RPC consumers |
| CVE-2026-106121 | 4.9 MEDIUM | RabbitMQ: JSONReader in the default JSON-RPC mapper never terminates on truncated input, c |
No comments yet