PT-2026-93796 · Github · Amqp091-Go

CVE-2026-77406

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description A resource exhaustion issue exists in the Quality of Service configuration. The Qos() function in channel.go accepts signed integers for the prefetchCount and prefetchSize parameters but casts them directly to unsigned integers (uint16 and uint32) without validation. If negative values such as -1 are provided, they wrap to their maximum possible values (65535 and 4294967295). This can lead to a Denial of Service if an application allows untrusted configuration of these values, as the broker may deliver an excessive volume of messages, exhausting client memory and causing the application to crash.
Recommendations Update to version 1.13.0. Restrict the use of untrusted inputs when configuring the prefetchCount and prefetchSize parameters in the Qos() function.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103188
AZL-103287
CLEANSTART-2026-KU86839
CVE-2026-77406
ECHO-0CD4-3C49-5D6C
GHSA-RM6M-HRCW-JW33
GO-2026-6502

Affected Products

Amqp091-Go