CVE-2025-50200
RabbitMQ logs the HTTP Basic Auth header, exposing usernames and passwords
Technology
RabbitMQ
CVSS Score
5.5 / 10.0
Affected Versions
3.13.0 to 3.13.7; 4.0.0 to 4.0.7 (NVD: all versions before 4.0.8)
Upstream Fix
4.0.8 (public); 3.13.8 (commercial)
Published
June 19, 2025
OSSeva Coverage
Fixed upstream
Description
When an HTTP API request with Basic authentication fails, for example on a queue that does not exist, the node logged all request headers, including the Authorization header. That header is the base64 encoding of username:password, so anyone who can read the logs can recover the credentials. Fixed in 4.0.8 and in the commercial 3.13.8.
Is your RabbitMQ deployment affected?
If you're running 3.13.0 to 3.13.7; 4.0.0 to 4.0.7 (NVD: all versions before 4.0.8), you need this patch. Book a discovery call to get covered.