๐Ÿ” CVE Alert

CVE-2026-77412

UNKNOWN 0.0

RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A malicious or compromised broker can encode a value such as 0xFFFFFFFF, which becomes -1 and causes a len out of range runtime panic. The panic escapes the network reader goroutine and terminates the client process, including during connection.start server properties or message header table parsing. This issue is fixed in version 1.13.0.

CWE CWE-681
Vendor rabbitmq
Product amqp091-go
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for rabbitmq amqp091-go

Be the first to know when new unknown vulnerabilities affecting rabbitmq amqp091-go are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

rabbitmq / amqp091-go
< 1.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3 github.com: https://github.com/rabbitmq/amqp091-go/pull/344 github.com: https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf github.com: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0