PT-2026-93794 · Rabbitmq · Amqp091-Go
CVE-2026-77404
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
8.7
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ amqp091-go versions prior to 1.13.0
Description
A query parameter injection issue exists in the connection URI formatting logic. The
URI.String function in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string without proper URL encoding. If an application accepts a TLS asset path containing ampersand (&) or equals (=) delimiters and subsequently reparses the serialized URI using the ParseURI() function, these delimiters can be interpreted as parameter separators. This allows the creation or overwriting of connection options, which can lead to the selection of unintended local cryptographic assets or the corruption of connection configurations.Recommendations
Update RabbitMQ amqp091-go to version 1.13.0.
Exploit
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amqp091-Go