Shovel and Federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret.
This means that in case of certain exceptions related to Shovel and Federation plugins, reasonably easily deobfuscatable data could appear in the node log.
Patched versions correctly use a cluster-wide secret for that purpose.
Patched versions:
3.10.23.9.183.8.32Disable Shovel and Federation plugins.
RabbitMQ core team would like to thank Lajos @luos Gerecs and Anh Nguyen from Erlang Solutions for responsibly disclosing and working with us on a patch for this vulnerability.
{
"github_reviewed": true,
"cwe_ids": [
"CWE-330",
"CWE-335"
],
"severity": "MODERATE",
"github_reviewed_at": "2026-06-30T16:15:48Z",
"nvd_published_at": "2022-10-06T18:16:00Z"
}