PT-2026-93800 · Unknown · Amqp091-Go

CVE-2026-77410

·

Published

2026-09-16

·

Updated

2026-10-01

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions RabbitMQ amqp091-go versions prior to 1.13.0
Description A flaw in the recvContent() function allows a malicious or compromised AMQP broker to trigger an Out-of-Memory (OOM) error, which is a state where the system lacks enough memory to perform operations, forcing the host operating system or container runtime to terminate the client process. The issue occurs because the client pre-allocates the message body slice using the ch.header.Size variable supplied by an AMQP content header without capping the allocation to the negotiated Connection.Config.FrameSize value. By sending an extreme declared body size, an attacker can cause the Go runtime to attempt a massive memory allocation, exhausting system resources and destroying application availability.
Recommendations Update RabbitMQ amqp091-go to version 1.13.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103185
AZL-103299
CLEANSTART-2026-BW44579
CVE-2026-77410
GHSA-R9C8-GCJP-XFWH
GO-2026-6500

Affected Products

Amqp091-Go