CVE-2026-67221: Rabbitmq Rabbitmq-Server

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The AMQP 0-9-1 shovel calls amqp_uri:remove_credentials before storing its connection URI, but the AMQP 1.0 shovel stores the raw URI including the password. The stored URI is visible via GET /api/shovels and via rabbitmqctl shovel_status. Preconditions include The Shovel plugin must be in use with AMQP 1.0 shovels configured using URI-embedded credentials. Reading the exposed status requires the monitoring tag.. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0.

Affected products

  • Rabbitmq Rabbitmq-Server: from 3.13.0, before 3.13.15 (fixed in 3.13.15); from 4.0.0, before 4.0.20 (fixed in 4.0.20); from 4.1.0, before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.6 (fixed in 4.2.6)

Published 2026-09-23. Last modified 2026-09-24.