AMQP 0.9.1 Go Client Vulnerability in RabbitMQ
CVE-2026-107386
6.3MEDIUM
What is CVE-2026-107386?
The amqp091-go client for Go is vulnerable due to a flaw that allows a malicious AMQP peer to exploit the frame size negotiation process. From versions 1.13.0 to 1.14.0, an attacker can craft a short body-frame header with a larger declared payload length, leading to improper memory allocation before the payload is fully processed. This occurs even when the configuration is set to the minimum protocol size, potentially resulting in severe memory pressure, premature out-of-memory terminations, or client crashes prior to successful authentication. Users are advised to upgrade to version 1.14.0, which rectifies this issue.
Affected Version(s)
amqp091-go >= 1.13.0, < 1.14.0
