PT-2026-102744 · Bitnami · Rabbitmq-C
Published
2026-09-29
·
Updated
2026-09-29
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size t underflow in amqp handle input() in librabbitmq/amqp connection.c. The parser subtracts HEADER SIZE, fixed per-frame fields, and FOOTER SIZE from state->target size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp decode properties() to amqp decode table internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or code execution shown. This issue is fixed in version 0.16.0.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rabbitmq-C