Memory Consumption Issue in amqp091-go Client from RabbitMQ
CVE-2026-79921
8.9HIGH
What is CVE-2026-79921?
The amqp091-go client, utilized for AMQP 0.9.1 communication, is susceptible to a vulnerability where a compromised AMQP broker can manipulate the client to allocate excessive resources. This occurs when the client is coerced into processing content body frames that surpass the defined frame_max limit. The result is unexpected memory consumption, which could lead to application-layer denial of service, effectively bypassing the native framing constraints stipulated by the AMQP protocol. The issue has been resolved in version 1.13.0, with no known workarounds before this update.
Affected Version(s)
amqp091-go < 1.13.0
