Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.5

CVE-2026-77411: RabbitMQ amqp091-go client misinterprets oversized strings

CVE-2026-77411 · published 23 days ago
Summary

The RabbitMQ amqp091-go Go client library can read a very large string incorrectly, leaving extra data unread and causing the rest of the communication to become out of sync. This can let a compromised broker disrupt the connection or cause unexpected behavior. Upgrade to version 1.13.0 or later to fix the issue.

What to do
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
  • Update github.com rabbitmq to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
  • Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
  • Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
  • Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
Affected software
Ecosystem VendorProductAffected versions
– rabbitmq amqp091-go < 1.13.0
Root:Go rabbitmq github.com/rabbitmq/amqp091-go < v1.10.0-aikido.5
< v1.10.0-aikido.6
< v1.12.0-aikido.5
< v1.12.0-aikido.6
Fix: upgrade to v1.10.0-aikido.5
Root:Go rabbitmq rootio-github.com/rabbitmq/amqp091-go < v1.10.0-root.io.5
< v1.10.0-root.io.6
< v1.12.0-root.io.5
< v1.12.0-root.io.6
Fix: upgrade to v1.10.0-root.io.5
go github.com rabbitmq < 1.13.0
Fix: upgrade to 1.13.0
Go rabbitmq github.com/rabbitmq/amqp091-go < 1.13.0
Fix: upgrade to 1.13.0
Debian:12 debian golang-github-rabbitmq-amqp091-go All versions
Debian:14 debian golang-github-rabbitmq-amqp091-go < 1.14.0-1
Fix: upgrade to 1.14.0-1
Original advisory text
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.5 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-754Improper Check for Unusual or Exceptional Conditions
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta