Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-77405: RabbitMQ amqp091-go may use outdated TLS versions
CVE-2026-77405 · published 23 days ago
Summary
The RabbitMQ amqp091-go client library can connect using old encryption protocols if it is built with an older Go runtime. This could let a network attacker weaken the security of your messages and login data. Upgrade to version 1.13.0 or later to ensure only modern TLS versions are used.
What to do
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
- Update github.com rabbitmq to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
- Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | amqp091-go | < 1.13.0 |
| Root:Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< v1.10.0-aikido.5 < v1.10.0-aikido.6 < v1.12.0-aikido.5 < v1.12.0-aikido.6 Fix: upgrade to v1.10.0-aikido.5
|
| Root:Go | rabbitmq | rootio-github.com/rabbitmq/amqp091-go |
< v1.10.0-root.io.5 < v1.10.0-root.io.6 < v1.12.0-root.io.5 < v1.12.0-root.io.6 Fix: upgrade to v1.10.0-root.io.5
|
| go | github.com | rabbitmq |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Debian:12 | debian | golang-github-rabbitmq-amqp091-go | All versions |
| Debian:14 | debian | golang-github-rabbitmq-amqp091-go |
< 1.14.0-1 Fix: upgrade to 1.14.0-1
|
Original advisory text
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.
References
- https://github.com/rabbitmq/amqp091-go/commit/c9fd433ecac2e557919e51acc9d809390c...
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-33mj-cw25-m34h
- https://github.com/rabbitmq/amqp091-go/pull/355
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77405... Vendor Advisory
- https://github.com/advisories/GHSA-33mj-cw25-m34h
- https://github.com/rabbitmq/amqp091-go Product
- https://security-tracker.debian.org/tracker/CVE-2026-77405 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-77405
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.4
Critical
Type
CWE-326Inadequate Encryption Strength
CWE-316Cleartext Storage of Sensitive Information in Memory
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-77405 · NVD
CVE-2026-77405 · MITRE
CVE-2026-77405 · OSV
GHSA-33mj-cw25-m34h · GHSA
GHSA-33mj-cw25-m34h · OSV
DEBIAN-CVE-2026-77405 · OSV
GO-2026-6492 · OSV
Track software like this
Free during beta