PT-2026-93795 · Rabbitmq · Amqp091-Go
CVE-2026-77405
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
RabbitMQ amqp091-go versions prior to 1.13.0
Description
A security weakness exists in the
tlsConfigFromURI function within uri.go when constructing a tls.Config object from an amqps:// connection URI. The library fails to explicitly set the MinVersion field to tls.VersionTLS12. Consequently, applications compiled with a Go runtime that permits TLS 1.0 or 1.1 may negotiate these obsolete protocol versions during the connection handshake. A network attacker performing a Man-in-the-Middle (MitM) attack can force a protocol downgrade, potentially exposing AMQP messages and authentication credentials to cryptographic vulnerabilities such as BEAST, POODLE, or SWEET32, which may allow the attacker to decrypt or alter the data stream.Recommendations
Update RabbitMQ amqp091-go to version 1.13.0.
Exploit
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amqp091-Go