Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-77408: RabbitMQ amqp091-go truncates long message metadata

CVE-2026-77408 · published 23 days ago
Summary

The RabbitMQ amqp091-go client can silently cut off metadata fields such as CorrelationId or MessageId when they exceed 255 characters, without warning. This can cause messages to lose their routing or tracking information, leading to processing errors. Upgrade to version 1.13.0 or later to prevent the truncation.

What to do
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
  • Update github.com rabbitmq to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
  • Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
Affected software
Ecosystem VendorProductAffected versions
– rabbitmq amqp091-go < 1.13.0
Root:Go rabbitmq github.com/rabbitmq/amqp091-go < v1.10.0-aikido.5
< v1.10.0-aikido.6
< v1.12.0-aikido.5
< v1.12.0-aikido.6
Fix: upgrade to v1.10.0-aikido.5
Root:Go rabbitmq rootio-github.com/rabbitmq/amqp091-go < v1.10.0-root.io.5
< v1.10.0-root.io.6
< v1.12.0-root.io.5
< v1.12.0-root.io.6
Fix: upgrade to v1.10.0-root.io.5
go github.com rabbitmq < 1.13.0
Fix: upgrade to 1.13.0
Go rabbitmq github.com/rabbitmq/amqp091-go < 1.13.0
Fix: upgrade to 1.13.0
Debian:12 debian golang-github-rabbitmq-amqp091-go All versions
Debian:14 debian golang-github-rabbitmq-amqp091-go < 1.14.0-1
Fix: upgrade to 1.14.0-1
Original advisory text
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
Fix within
Internet-facing 14 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker partial control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-190Integer Overflow
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta