Denial of Service Risk in RabbitMQ AMQP Client by RabbitMQ
CVE-2026-77411
9.5CRITICAL
What is CVE-2026-77411?
A flaw in RabbitMQ's amqp091-go client permits a malicious broker to send oversized 'longstr' values in a table field. This causes subsequent AMQP parsing to desynchronize, allowing attacker-controlled data to interfere with the parsing process. As a result, the integrity and availability of connections can be compromised. This vulnerability was addressed in version 1.13.0, which ensures proper error handling and parsing logic.
Affected Version(s)
amqp091-go < 1.13.0
