PT-2026-93795 · Rabbitmq · Amqp091-Go

CVE-2026-77405

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

9.4

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description A security weakness exists in the tlsConfigFromURI function within uri.go when constructing a tls.Config object from an amqps:// connection URI. The library fails to explicitly set the MinVersion field to tls.VersionTLS12. Consequently, applications compiled with a Go runtime that permits TLS 1.0 or 1.1 may negotiate these obsolete protocol versions during the connection handshake. A network attacker performing a Man-in-the-Middle (MitM) attack can force a protocol downgrade, potentially exposing AMQP messages and authentication credentials to cryptographic vulnerabilities such as BEAST, POODLE, or SWEET32, which may allow the attacker to decrypt or alter the data stream.
Recommendations Update RabbitMQ amqp091-go to version 1.13.0.

Exploit

Fix

Inadequate Encryption Strength

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103182
AZL-103284
CLEANSTART-2026-AD74285
CVE-2026-77405
GHSA-33MJ-CW25-M34H
GO-2026-6492

Affected Products

Amqp091-Go