{"id":"CVE-2026-63336","aliases":["GHSA-5m9f-rphj-c435"],"url":"https://o3.security/vulnerability/CVE-2026-63336","summary":"RabbitMQ Java client: TrustEverythingTrustManager used by default in useSslProtocol() enables MITM","details":"## Vulnerability Summary\n\n`com.rabbitmq.client.TrustEverythingTrustManager` accepts ANY TLS certificate (including null chains) and is used as the default trust manager when calling `ConnectionFactory.useSslProtocol()` without arguments. Combined with hostname verification being disabled by default, this enables trivial man-in-the-middle attacks.\n\n## Affected Components\n\n- `com.rabbitmq.client.TrustEverythingTrustManager` — accepts any certificate\n- `com.rabbitmq.client.ConnectionFactory.useSslProtocol()` — uses TrustEverythingTrustManager\n- Hostname verification disabled by default (`enableHostnameVerification()` must be called explicitly)\n- `com.rabbitmq.client.ConnectionFactory.getPassword()` — returns plaintext with no redaction\n- Default port 5672 (plaintext) with PLAIN SASL — credentials sent unencrypted\n\n## POC (Verified on Java 21, amqp-client 5.25.0)\n\n```java\n// TrustEverythingTrustManager accepts ANY certificate including null\nTrustEverythingTrustManager tm = new TrustEverythingTrustManager();\ntm.checkServerTrusted(null, \"RSA\");  // No exception — accepts null cert chain\ntm.getAcceptedIssuers();  // Returns empty array — trusts all CAs\n\n// ConnectionFactory defaults\nConnectionFactory factory = new ConnectionFactory();\nfactory.useSslProtocol();  // Uses TrustEverythingTrustManager internally\n// enableHostnameVerification() NOT called by default\n\n// Credential exposure\nfactory.setPassword(\"secret_password_123\");\nfactory.getPassword();  // Returns \"secret_password_123\" — no redaction\n\n// Default plaintext port\nfactory.getPort();  // 5672 (plaintext, not 5671/TLS)\n\n// PLAIN SASL sends cleartext credentials\nPlainMechanism pm = new PlainMechanism();\n// handleChallenge() sends username+password in cleartext\n```\n\n## Attack Scenarios\n\n1. **MITM**: Attacker presents self-signed cert → `TrustEverythingTrustManager` accepts it → all RabbitMQ traffic intercepted\n2. **Credential theft**: Default plaintext port (5672) + PLAIN SASL = credentials readable on network\n3. **DNS rebinding**: No hostname verification → attacker DNS record → MITM without cert\n4. **Logging exposure**: `getPassword()` returns plaintext → credentials in logs/stack traces\n\n## Suggested Fix\n1. Deprecate `TrustEverythingTrustManager` — it should never be used in production\n2. `useSslProtocol()` should use the JVM default trust store, not TrustEverything\n3. Enable hostname verification by default\n4. Redact password in `getPassword()` or remove the public getter\n5. Warn when using PLAIN SASL without TLS","published":"2026-08-18T16:29:23.115Z","modified":"2026-09-12T08:08:20.214341Z","cvss":null,"epss":{"score":0.00182,"percentile":0.08,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.rabbitmq:amqp-client","fixedVersion":"5.33.0"}],"fix":{"url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339","label":"rabbitmq/rabbitmq-java-client@1e7deb2"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/rabbitmq-java-client/releases/tag/v5.33.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63336.json"},{"type":"ADVISORY","url":"https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63336"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/1999"},{"type":"FIX","url":"https://github.com/rabbitmq/rabbitmq-java-client/pull/2001"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/rabbitmq-java-client"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-12T08:08:20.214341Z"}}