{"id":"GHSA-h6w7-qmcm-q6xr","summary":"RabbitMQ Java client: plaintext broker credentials leaked in exception message from ConnectionFactoryConfigurator.load()","details":"### Summary\nWhen property-file/Map-based `ConnectionFactory` setup fails while parsing the `uri` key, the library wraps the underlying exception with the raw connection string — including the plaintext username and password — baked verbatim into the new exception's message.\n\n### Details\n`ConnectionFactoryConfigurator.load(ConnectionFactory, Map\u003cString,String\u003e, String)` (`src/main/java/com/rabbitmq/client/ConnectionFactoryConfigurator.java`, lines 142-155):\n\n    String uri = properties.get(prefix + \"uri\");\n    if (uri != null) {\n        try {\n            cf.setUri(uri);\n        } catch (URISyntaxException e) {\n            throw new IllegalArgumentException(\"Error while setting AMQP URI: \" + uri, e);\n        } catch (NoSuchAlgorithmException e) {\n            throw new IllegalArgumentException(\"Error while setting AMQP URI: \" + uri, e);\n        } catch (KeyManagementException e) {\n            throw new IllegalArgumentException(\"Error while setting AMQP URI: \" + uri, e);\n        }\n    }\n\n`uri` is the full AMQP URI — `amqp(s)://username:password@host:port/vhost` — concatenated verbatim into the exception message on any of the three catch branches. No masking/redaction exists anywhere in this class or in `ConnectionFactory.setUri()`. This is the library's documented Spring-Boot/ops-config entry point (`ConnectionFactory.load(...)`, available since 4.4.0), not obscure internal code.\n\nRabbitMQ's own AMQP URI spec (rabbitmq.com/docs/uri-spec) explicitly warns the password \"should avoid leaking... the full URI should not appear in exception messages or log records.\" A sibling method twenty lines away (`ConnectionFactory.setUri(URI)`) already avoids this exact mistake for a different malformed-URI case — this path wasn't caught by that same care.\n\nNote: `KeyManagementException` is declared in the throws clause but not actually reachable via the current `setUri(String)` → `setUri(URI)` call chain — the two real, reachable leak surfaces are the `URISyntaxException` branch (trivial, deterministic, scheme-independent) and the `NoSuchAlgorithmException` branch (real but narrower — `amqps://` only, requires a restricted/FIPS-style default TLS provider).\n\n### PoC\n    Map\u003cString, String\u003e props = new HashMap\u003c\u003e();\n    props.put(\"uri\", \"amqp://svc-account:P@ssW0rd With Space!@broker.internal:5672/prod\");\n    ConnectionFactory cf = new ConnectionFactory();\n    ConnectionFactoryConfigurator.load(cf, props, \"\");\n\nThrows:\n\n    java.lang.IllegalArgumentException: Error while setting AMQP URI: amqp://svc-account:P@ssW0rd With Space!@broker.internal:5672/prod\n\nA password containing a space is entirely ordinary under common corporate password policies, and `java.net.URI` rejects such input outright — this isn't a contrived edge case.\n\n### Impact\nDefault Spring Boot startup-failure logging, an APM/error tracker, a CI job log, or an engineer pasting a stack trace into an internal or public ticket now holds the plaintext broker password, in a system typically far less access-controlled than wherever the credential is normally stored. Note the underlying `URISyntaxException` also carries the same string in its own message, chained as the cause of RabbitMQ's `IllegalArgumentException` — so removing RabbitMQ's own `+ uri` concatenation alone would not fully close this; the raw secret-bearing string also shouldn't be handed to `new URI()` for error-reporting purposes at all.\n\nSuggested fix: don't include the raw `uri` string in the wrapped exception's message — redact the userinfo component (or omit the URI entirely) before including it in any exception text.","aliases":["CVE-2026-106123"],"modified":"2026-10-07T16:30:05.336767383Z","published":"2026-10-07T16:19:22Z","database_specific":{"github_reviewed_at":"2026-10-07T16:19:22Z","nvd_published_at":"2026-10-06T19:17:43Z","cwe_ids":["CWE-509"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-h6w7-qmcm-q6xr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106123"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2052"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/daca1875cdb8b8c0acce78f71103b21a05478446"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"},{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.35.0"}],"affected":[{"package":{"name":"com.rabbitmq:amqp-client","ecosystem":"Maven","purl":"pkg:maven/com.rabbitmq/amqp-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.35.0"}]}],"versions":["1.3.0","1.5.4","1.5.5","1.6.0","1.7.2","1.8.0","1.8.1","2.0.0","2.1.0","2.1.1","2.2.0","2.3.0","2.3.1","2.4.1","2.5.0","2.5.1","2.6.0","2.6.1","2.7.0","2.7.1","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","3.0.0","3.0.1","3.0.2","3.0.3","3.0.4","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.3.5","3.4.0","3.4.1","3.4.2","3.4.3","3.4.4","3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","4.0.0","4.0.1","4.0.2","4.0.3","4.1.0","4.1.1","4.10.0","4.11.0","4.11.1","4.11.2","4.11.3","4.12.0","4.2.0","4.2.1","4.2.2","4.3.0","4.4.0","4.4.1","4.4.2","4.5.0","4.6.0","4.7.0","4.8.0","4.8.1","4.8.2","4.8.3","4.9.0","4.9.1","4.9.2","4.9.3","5.0.0","5.1.0","5.1.1","5.1.2","5.10.0","5.11.0","5.12.0","5.13.0","5.13.1","5.14.0","5.14.1","5.14.2","5.14.3","5.15.0","5.16.0","5.16.1","5.17.0","5.17.1","5.18.0","5.19.0","5.2.0","5.20.0","5.21.0","5.22.0","5.23.0","5.24.0","5.25.0","5.26.0","5.27.0","5.27.1","5.28.0","5.29.0","5.3.0","5.30.0","5.31.0","5.32.0","5.33.0","5.33.1","5.34.0","5.4.0","5.4.1","5.4.2","5.4.3","5.5.0","5.5.1","5.5.2","5.5.3","5.6.0","5.7.0","5.7.1","5.7.2","5.7.3","5.8.0","5.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-h6w7-qmcm-q6xr/GHSA-h6w7-qmcm-q6xr.json","last_known_affected_version_range":"\u003c= 5.34.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}