PT-2026-93801 · Unknown · Amqp091-Go
CVE-2026-77411
·
Published
2026-09-16
·
Updated
2026-10-01
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
RabbitMQ amqp091-go versions prior to 1.13.0
Description
A stream desynchronization issue exists in the AMQP wire-protocol parser. When the
readLongstr() function in read.go encounters a declared AMQP longstr length exceeding 0x7FFFFFFF (the maximum signed 32-bit integer), it returns an empty string and a nil error instead of returning ErrSyntax. This behavior leaves the declared field bytes unread in the network buffer. Consequently, the readTable() function treats the operation as successful and continues parsing from an incorrect offset. A malicious or compromised broker can exploit this by providing an oversized longstr in a table field, causing subsequent AMQP parsing to be misaligned. This allows attacker-controlled trailing bytes to be misinterpreted as valid AMQP frame headers or fields, potentially leading to data injection, connection hijacking, or disruption of connection integrity and availability.Recommendations
Update RabbitMQ amqp091-go to version 1.13.0.
Exploit
Fix
DoS
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amqp091-Go