Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-50200

RabbitMQ logs the HTTP Basic Auth header, exposing usernames and passwords

Technology

RabbitMQ

CVSS Score

5.5 / 10.0

Affected Versions

3.13.0 to 3.13.7; 4.0.0 to 4.0.7 (NVD: all versions before 4.0.8)

Upstream Fix

4.0.8 (public); 3.13.8 (commercial)

Published

June 19, 2025

OSSeva Coverage

Fixed upstream

Description

When an HTTP API request with Basic authentication fails, for example on a queue that does not exist, the node logged all request headers, including the Authorization header. That header is the base64 encoding of username:password, so anyone who can read the logs can recover the credentials. Fixed in 4.0.8 and in the commercial 3.13.8.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running 3.13.0 to 3.13.7; 4.0.0 to 4.0.7 (NVD: all versions before 4.0.8), you need this patch. Book a discovery call to get covered.