Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-77408: RabbitMQ amqp091-go truncates long message metadata
CVE-2026-77408 · published 23 days ago
Summary
The RabbitMQ amqp091-go client can silently cut off metadata fields such as CorrelationId or MessageId when they exceed 255 characters, without warning. This can cause messages to lose their routing or tracking information, leading to processing errors. Upgrade to version 1.13.0 or later to prevent the truncation.
What to do
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
- Update github.com rabbitmq to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
- Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | amqp091-go | < 1.13.0 |
| Root:Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< v1.10.0-aikido.5 < v1.10.0-aikido.6 < v1.12.0-aikido.5 < v1.12.0-aikido.6 Fix: upgrade to v1.10.0-aikido.5
|
| Root:Go | rabbitmq | rootio-github.com/rabbitmq/amqp091-go |
< v1.10.0-root.io.5 < v1.10.0-root.io.6 < v1.12.0-root.io.5 < v1.12.0-root.io.6 Fix: upgrade to v1.10.0-root.io.5
|
| go | github.com | rabbitmq |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Debian:12 | debian | golang-github-rabbitmq-amqp091-go | All versions |
| Debian:14 | debian | golang-github-rabbitmq-amqp091-go |
< 1.14.0-1 Fix: upgrade to 1.14.0-1
|
Original advisory text
RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
References
- https://github.com/rabbitmq/amqp091-go/pull/354
- https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065de...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77408... Vendor Advisory
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x
- https://nvd.nist.gov/vuln/detail/CVE-2026-77408
- https://github.com/advisories/GHSA-j497-x9hr-x34x
- https://github.com/rabbitmq/amqp091-go Product
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
- https://security-tracker.debian.org/tracker/CVE-2026-77408 Vendor Advisory
Internet-facing
14 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker partial control
Severity
9.1
Critical
Type
CWE-190Integer Overflow
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-77408 · NVD
CVE-2026-77408 · MITRE
CVE-2026-77408 · OSV
GHSA-j497-x9hr-x34x · GHSA
GHSA-j497-x9hr-x34x · OSV
DEBIAN-CVE-2026-77408 · OSV
GO-2026-6498 · OSV
Track software like this
Free during beta