Memory Consumption Issue in amqp091-go Client from RabbitMQ
CVE-2026-79921

8.9HIGH

Key Information:

Vendor

RabbitMQ

Vendor
CVE Published:
26 August 2026

What is CVE-2026-79921?

The amqp091-go client, utilized for AMQP 0.9.1 communication, is susceptible to a vulnerability where a compromised AMQP broker can manipulate the client to allocate excessive resources. This occurs when the client is coerced into processing content body frames that surpass the defined frame_max limit. The result is unexpected memory consumption, which could lead to application-layer denial of service, effectively bypassing the native framing constraints stipulated by the AMQP protocol. The issue has been resolved in version 1.13.0, with no known workarounds before this update.

Affected Version(s)

amqp091-go < 1.13.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.