PT-2026-93800 · Unknown · Amqp091-Go
CVE-2026-77410
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
RabbitMQ amqp091-go versions prior to 1.13.0
Description
A flaw in the
recvContent() function allows a malicious or compromised AMQP broker to trigger an Out-of-Memory (OOM) error, which is a state where the system lacks enough memory to perform operations, forcing the host operating system or container runtime to terminate the client process. The issue occurs because the client pre-allocates the message body slice using the ch.header.Size variable supplied by an AMQP content header without capping the allocation to the negotiated Connection.Config.FrameSize value. By sending an extreme declared body size, an attacker can cause the Go runtime to attempt a massive memory allocation, exhausting system resources and destroying application availability.Recommendations
Update RabbitMQ amqp091-go to version 1.13.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amqp091-Go