PT-2026-93799 · Rabbitmq · Amqp091-Go

CVE-2026-77409

·

Published

2026-09-16

·

Updated

2026-09-18

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description The Channel.dispatch function in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, consumer cancellations, and returned messages (including NotifyConfirm events and connection block notifications) to application-provided channels. If a listener channel is unbuffered, full, or not drained promptly, the sole reader goroutine blocks and stops processing frames, acknowledgments, deliveries, and heartbeats. This can lead to connection stalls, missed heartbeats, deadlocks, and disconnection during broker-driven event bursts.
Recommendations Update to version 1.13.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103197
AZL-103281
CVE-2026-77409
GHSA-WXX3-CJ7G-W73J

Affected Products

Amqp091-Go