PT-2026-93793 · Unknown · Amqp091-Go

CVE-2026-77403

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description A Denial of Service (DoS) issue exists in the connection negotiation logic. The client fails to enforce the AMQP protocol minimum frame size of 4096 bytes, defined by the frameMinSize constant, and blindly accepts the FrameMax value advertised by the server during the handshake. If a client connects to a malicious or compromised AMQP broker that advertises an extremely small FrameMax, subsequent message transmissions are fragmented into an excessive number of frames and write operations. This process occurs within the Connection.openTune() function in connection.go. The resulting massive CPU overhead and resource starvation can stall the client application or the entire host system.
Recommendations Update RabbitMQ amqp091-go to version 1.13.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103209
AZL-103296
CLEANSTART-2026-QD76067
CVE-2026-77403
ECHO-4C9A-DE8F-1909
GHSA-XWWF-M8FG-P9Q2
GO-2026-6503

Affected Products

Amqp091-Go