Network Management
Why SolarWinds Observability Self-Hosted is not affected by CVE-2025-50200
This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2025-50200.
First published date
Last published date
Overview
In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2025-50200.
RabbitMQ is a messaging and streaming broker. In versions 3.13.7 and prior, RabbitMQ is logging authorization headers in plaintext encoded in base64. When querying the RabbitMQ API (with HTTP/s with basic authentication), it creates logs with all headers in the request, including authorization headers which show base64 encoded username:password. This is easy to decode and could be used to obtain control of the system depending on credentials.
Product section
Cause
CVE-2025-50200.
Resolution
RabbitMQ files can only be seen by highly privileged users with local access to the server itself. We are not affected due to the requirement of the API, which is not used in our instance.