AMQP 0.9.1 Go Client Vulnerability in RabbitMQ
CVE-2026-107386

6.3MEDIUM

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107386?

The amqp091-go client for Go is vulnerable due to a flaw that allows a malicious AMQP peer to exploit the frame size negotiation process. From versions 1.13.0 to 1.14.0, an attacker can craft a short body-frame header with a larger declared payload length, leading to improper memory allocation before the payload is fully processed. This occurs even when the configuration is set to the minimum protocol size, potentially resulting in severe memory pressure, premature out-of-memory terminations, or client crashes prior to successful authentication. Users are advised to upgrade to version 1.14.0, which rectifies this issue.

Affected Version(s)

amqp091-go >= 1.13.0, < 1.14.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.