CVE-2026-77407
CVE-2026-77407 is a high-severity vulnerability with a CVSS 4.0 base score of 7.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-316.
Key facts
- Severity: High (CVSS 4.0 base score 7.0)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-316
- Published:
- Last modified:
Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection.openComplete method in connection.go does not clear those values. Code with access to the Connection object, including reflective loggers, application performance monitoring agents, debugging utilities, and panic handlers, can traverse the configuration and expose the credentials to logs or state captures. The credential remains available for the lifetime of the connection instead of being cleared after authentication. This issue is fixed in version 1.13.0.
Frequently asked questions
- What is CVE-2026-77407?
- RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection.openComplete method in connection.go does not clear those values. Code with access to the Connection object, including reflective loggers, application performance monitoring agents, debugging utilities, and panic handlers, can traverse the configuration and expose the credentials to logs or state captures. The credential remains available for the lifetime of the connection instead of being cleared after authentication. This issue is fixed in version 1.13.0.
- How severe is CVE-2026-77407?
- CVE-2026-77407 has a CVSS 4.0 base score of 7.0, rated high severity.
- Is CVE-2026-77407 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-77407?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-77407 published?
- CVE-2026-77407 was published on 2026-09-16 and last updated on 2026-09-23.
References
- https://github.com/rabbitmq/amqp091-go/commit/fa013b8447eb60988db3c9281ff6b981e4d2fb4f
- https://github.com/rabbitmq/amqp091-go/pull/350
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-27gv-rfvv-22mv
Other CWE-316 vulnerabilities
- CVE-2025-52579 — Critical (CVSS 9.4): Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to…
- CVE-2014-2366 — Critical (CVSS 9.0): upAdminPg.asp in Advantech WebAccess before 7.2 allows remote authenticated users to discover credentials by reading…
- CVE-2024-36792 — High (CVSS 8.2): An issue in the implementation of the WPS in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to gain…
- CVE-2025-50109 — High (CVSS 7.7): Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to…
- CVE-2025-9970 — High (CVSS 7.4): Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through…
- CVE-2023-40724 — High (CVSS 7.3): A vulnerability has been identified in QMS Automotive (All versions < V12.39). User credentials are found in memory as…