PT-2026-108149 · Unknown · Amqp091-Go
CVE-2026-107386
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
amqp091-go versions 1.13.0 through 1.13.x
Description
A frame-size mitigation can be bypassed before the
connection.tune process completes. A malicious or compromised AMQP peer can send a short body-frame header containing a large attacker-controlled uint32 payload length. Because the Connection.maxFrameSize variable is initialized to zero, the reader interprets this as either a not-yet-negotiated or a negotiated-unlimited state, skipping the pre-allocation size check.This allows the
ReadFrame function and the parseBodyFrame() function to allocate a memory slice based on the attacker-selected length before the payload is actually received or the frame's protocol state is rejected. This condition is reachable through the public Open function, even when Config.FrameSize is set to the protocol minimum. An attacker can request allocations approaching 4 GiB, leading to severe memory pressure, out-of-memory (OOM) termination, or loss of the client process before authentication is completed.Recommendations
Update to version 1.14.0.
As a temporary mitigation, restrict access to the AMQP broker to trusted peers only to prevent malicious frame headers from being sent during connection establishment.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amqp091-Go