ghsa-5m9f-rphj-c435
CVSS 5.1 osv_maven## Vulnerability Summary `com.rabbitmq.client.TrustEverythingTrustManager` accepts ANY TLS certificate (including null chains) and is used as the default trust manager when calling `ConnectionFactory.useSslProtocol()` without arguments. Combined with hostname verification being disabled by default, this enables trivial man-in-the-middle attacks. ## Affected Components - `com.rabbitmq.client.TrustEverythingTrustManager` — accepts any certificate - `com.rabbitmq.client.ConnectionFactory.useSslProtocol()` — uses TrustEverythingTrustManager - Hostname verification disabled by default (`enableHostnameVerification()` must be called explicitly) - `com.rabbitmq.client.ConnectionFactory.getPassword()` — returns plaintext with no redaction - Default port 5672 (plaintext) with PLAIN SASL — credentials sent unencrypted ## POC (Verified on Java 21, amqp-client 5.25.0) ```java // TrustEverythingTrustManager accepts ANY certificate including null TrustEverythingTrustManager tm = new TrustEverythingTrustManager(); tm.checkServerTrusted(null, "RSA"); // No exception — accepts null cert chain tm.getAcceptedIssuers(); // Returns empty array — trusts all CAs // ConnectionFactory defaults ConnectionFactory factory = new ConnectionFactory(); factory.useSslProtocol(); // Uses TrustEverythingTrustManager internally // enableHostnameVerification() NOT called by default // Credential exposure factory.setPassword("secret_password_123"); factory.getPassword(); // Returns "secret_password_123" — no redaction // Default plaintext port factory.getPort(); // 5672 (plaintext, not 5671/TLS) // PLAIN SASL sends cleartext credentials PlainMechanism pm = new PlainMechanism(); // handleChallenge() sends username+password in cleartext ``` ## Attack Scenarios 1. **MITM**: Attacker presents self-signed cert → `TrustEverythingTrustManager` accepts it → all RabbitMQ traffic intercepted 2. **Credential theft**: Default plaintext port (5672) + PLAIN SASL = credentials readable on network 3. **DNS rebinding**: No hostname verification → attacker DNS record → MITM without cert 4. **Logging exposure**: `getPassword()` returns plaintext → credentials in logs/stack traces ## Suggested Fix 1. Deprecate `TrustEverythingTrustManager` — it should never be used in production 2. `useSslProtocol()` should use the JVM default trust store, not TrustEverything 3. Enable hostname verification by default 4. Redact password in `getPassword()` or remove the public getter 5. Warn when using PLAIN SASL without TLS
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
- https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
- https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
- https://github.com/rabbitmq/rabbitmq-java-client/pull/2001
- https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339
- https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01
- https://github.com/rabbitmq/rabbitmq-java-client
- https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-5m9f-rphj-c435/GHSA-5m9f-rphj-c435.json"
},
"package": {
"ecosystem": "Maven",
"name": "com.rabbitmq:amqp-client",
"purl": "pkg:maven/com.rabbitmq/amqp-client"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.33.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"1.3.0",
"1.5.4",
"1.5.5",
"1.6.0",
"1.7.2",
"1.8.0",
"1.8.1",
"2.0.0",
"2.1.0",
"2.1.1",
"2.2.0",
"2.3.0",
"2.3.1",
"2.4.1",
"2.5.0",
"2.5.1",
"2.6.0",
"2.6.1",
"2.7.0",
"2.7.1",
"2.8.0",
"2.8.1",
"2.8.2",
"2.8.3",
"2.8.4",
"2.8.5",
"2.8.6",
"2.8.7",
"3.0.0",
"3.0.1",
"3.0.2",
"3.0.3",
"3.0.4",
"3.1.0",
"3.1.1",
"3.1.2",
"3.1.3",
"3.1.4",
"3.2.0",
"3.2.1",
"3.2.2",
"3.2.3",
"3.2.4",
"3.3.0",
"3.3.1",
"3.3.2",
"3.3.3",
"3.3.4",
"3.3.5",
"3.4.0",
"3.4.1",
"3.4.2",
"3.4.3",
"3.4.4",
"3.5.0",
"3.5.1",
"3.5.2",
"3.5.3",
"3.5.4",
"3.5.5",
"3.5.6",
"3.5.7",
"3.6.0",
"3.6.1",
"3.6.2",
"3.6.3",
"3.6.4",
"3.6.5",
"3.6.6",
"4.0.0",
"4.0.1",
"4.0.2",
"4.0.3",
"4.1.0",
"4.1.1",
"4.10.0",
"4.11.0",
"4.11.1",
"4.11.2",
"4.11.3",
"4.12.0",
"4.2.0",
"4.2.1",
"4.2.2",
"4.3.0",
"4.4.0",
"4.4.1",
"4.4.2",
"4.5.0",
"4.6.0",
"4.7.0",
"4.8.0",
"4.8.1",
"4.8.2",
"4.8.3",
"4.9.0",
"4.9.1",
"4.9.2",
"4.9.3",
"5.0.0",
"5.1.0",
"5.1.1",
"5.1.2",
"5.10.0",
"5.11.0",
"5.12.0",
"5.13.0",
"5.13.1",
"5.14.0",
"5.14.1",
"5.14.2",
"5.14.3",
"5.15.0",
"5.16.0",
"5.16.1",
"5.17.0",
"5.17.1",
"5.18.0",
"5.19.0",
"5.2.0",
"5.20.0",
"5.21.0",
"5.22.0",
"5.23.0",
"5.24.0",
"5.25.0",
"5.26.0",
"5.27.0",
"5.27.1",
"5.28.0",
"5.29.0",
"5.3.0",
"5.30.0",
"5.31.0",
"5.32.0",
"5.4.0",
"5.4.1",
"5.4.2",
"5.4.3",
"5.5.0",
"5.5.1",
"5.5.2",
"5.5.3",
"5.6.0",
"5.7.0",
"5.7.1",
"5.7.2",
"5.7.3",
"5.8.0",
"5.9.0"
]
}
],
"aliases": [
"CVE-2026-63336"
],
"database_specific": {
"cwe_ids": [
"CWE-295"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-18T16:32:59Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "## Vulnerability Summary\n\n`com.rabbitmq.client.TrustEverythingTrustManager` accepts ANY TLS certificate (including null chains) and is used as the default trust manager when calling `ConnectionFactory.useSslProtocol()` without arguments. Combined with hostname verification being disabled by default, this enables trivial man-in-the-middle attacks.\n\n## Affected Components\n\n- `com.rabbitmq.client.TrustEverythingTrustManager` — accepts any certificate\n- `com.rabbitmq.client.ConnectionFactory.useSslProtocol()` — uses TrustEverythingTrustManager\n- Hostname verification disabled by default (`enableHostnameVerification()` must be called explicitly)\n- `com.rabbitmq.client.ConnectionFactory.getPassword()` — returns plaintext with no redaction\n- Default port 5672 (plaintext) with PLAIN SASL — credentials sent unencrypted\n\n## POC (Verified on Java 21, amqp-client 5.25.0)\n\n```java\n// TrustEverythingTrustManager accepts ANY certificate including null\nTrustEverythingTrustManager tm = new TrustEverythingTrustManager();\ntm.checkServerTrusted(null, \"RSA\"); // No exception — accepts null cert chain\ntm.getAcceptedIssuers(); // Returns empty array — trusts all CAs\n\n// ConnectionFactory defaults\nConnectionFactory factory = new ConnectionFactory();\nfactory.useSslProtocol(); // Uses TrustEverythingTrustManager internally\n// enableHostnameVerification() NOT called by default\n\n// Credential exposure\nfactory.setPassword(\"secret_password_123\");\nfactory.getPassword(); // Returns \"secret_password_123\" — no redaction\n\n// Default plaintext port\nfactory.getPort(); // 5672 (plaintext, not 5671/TLS)\n\n// PLAIN SASL sends cleartext credentials\nPlainMechanism pm = new PlainMechanism();\n// handleChallenge() sends username+password in cleartext\n```\n\n## Attack Scenarios\n\n1. **MITM**: Attacker presents self-signed cert → `TrustEverythingTrustManager` accepts it → all RabbitMQ traffic intercepted\n2. **Credential theft**: Default plaintext port (5672) + PLAIN SASL = credentials readable on network\n3. **DNS rebinding**: No hostname verification → attacker DNS record → MITM without cert\n4. **Logging exposure**: `getPassword()` returns plaintext → credentials in logs/stack traces\n\n## Suggested Fix\n1. Deprecate `TrustEverythingTrustManager` — it should never be used in production\n2. `useSslProtocol()` should use the JVM default trust store, not TrustEverything\n3. Enable hostname verification by default\n4. Redact password in `getPassword()` or remove the public getter\n5. Warn when using PLAIN SASL without TLS",
"id": "GHSA-5m9f-rphj-c435",
"modified": "2026-09-10T03:51:13.150501327Z",
"published": "2026-08-18T16:32:59Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/1999"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/pull/2001"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01"
},
{
"type": "PACKAGE",
"url": "https://github.com/rabbitmq/rabbitmq-java-client"
},
{
"type": "WEB",
"url": "https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N",
"type": "CVSS_V4"
}
],
"summary": "RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM"
}