PT-2026-93794 · Rabbitmq · Amqp091-Go

CVE-2026-77404

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

8.7

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description A query parameter injection issue exists in the connection URI formatting logic. The URI.String function in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string without proper URL encoding. If an application accepts a TLS asset path containing ampersand (&) or equals (=) delimiters and subsequently reparses the serialized URI using the ParseURI() function, these delimiters can be interpreted as parameter separators. This allows the creation or overwriting of connection options, which can lead to the selection of unintended local cryptographic assets or the corruption of connection configurations.
Recommendations Update RabbitMQ amqp091-go to version 1.13.0.

Exploit

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-TU13335
CVE-2026-77404
GHSA-465G-FH3V-9JW4
GO-2026-6493

Affected Products

Amqp091-Go