Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-77405: RabbitMQ amqp091-go may use outdated TLS versions

CVE-2026-77405 · published 23 days ago
Summary

The RabbitMQ amqp091-go client library can connect using old encryption protocols if it is built with an older Go runtime. This could let a network attacker weaken the security of your messages and login data. Upgrade to version 1.13.0 or later to ensure only modern TLS versions are used.

What to do
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
  • Update github.com rabbitmq to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
  • Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
Affected software
Ecosystem VendorProductAffected versions
– rabbitmq amqp091-go < 1.13.0
Root:Go rabbitmq github.com/rabbitmq/amqp091-go < v1.10.0-aikido.5
< v1.10.0-aikido.6
< v1.12.0-aikido.5
< v1.12.0-aikido.6
Fix: upgrade to v1.10.0-aikido.5
Root:Go rabbitmq rootio-github.com/rabbitmq/amqp091-go < v1.10.0-root.io.5
< v1.10.0-root.io.6
< v1.12.0-root.io.5
< v1.12.0-root.io.6
Fix: upgrade to v1.10.0-root.io.5
go github.com rabbitmq < 1.13.0
Fix: upgrade to 1.13.0
Go rabbitmq github.com/rabbitmq/amqp091-go < 1.13.0
Fix: upgrade to 1.13.0
Debian:12 debian golang-github-rabbitmq-amqp091-go All versions
Debian:14 debian golang-github-rabbitmq-amqp091-go < 1.14.0-1
Fix: upgrade to 1.14.0-1
Original advisory text
RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-326Inadequate Encryption Strength
CWE-316Cleartext Storage of Sensitive Information in Memory
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta