PT-2026-93798 · Rabbitmq · Amqp091-Go
CVE-2026-77408
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
RabbitMQ amqp091-go versions prior to 1.13.0
Description
A data integrity and protocol corruption issue exists in the property serialization logic of the AMQP client. When encoding AMQP short string (
shortstr) fields, the writeShortstr() function in write.go casts the byte length of the property values to a uint8 without validating if the length exceeds 255 bytes. If an application accepts oversized values for properties such as CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type, the length counter silently wraps around due to integer truncation. This results in only a truncated prefix of the string being written to the connection buffer while reporting no error. This silent metadata corruption can lead to protocol desynchronization, breaking request and reply correlation, routing, tracing, and downstream message processing.Recommendations
Update RabbitMQ amqp091-go to version 1.13.0.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amqp091-Go