PT-2026-108149 · Unknown · Amqp091-Go

CVE-2026-107386

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions amqp091-go versions 1.13.0 through 1.13.x
Description A frame-size mitigation can be bypassed before the connection.tune process completes. A malicious or compromised AMQP peer can send a short body-frame header containing a large attacker-controlled uint32 payload length. Because the Connection.maxFrameSize variable is initialized to zero, the reader interprets this as either a not-yet-negotiated or a negotiated-unlimited state, skipping the pre-allocation size check.
This allows the ReadFrame function and the parseBodyFrame() function to allocate a memory slice based on the attacker-selected length before the payload is actually received or the frame's protocol state is rejected. This condition is reachable through the public Open function, even when Config.FrameSize is set to the protocol minimum. An attacker can request allocations approaching 4 GiB, leading to severe memory pressure, out-of-memory (OOM) termination, or loss of the client process before authentication is completed.
Recommendations Update to version 1.14.0. As a temporary mitigation, restrict access to the AMQP broker to trusted peers only to prevent malicious frame headers from being sent during connection establishment.

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107386
GHSA-W6R9-248C-FRG8

Affected Products

Amqp091-Go