Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-77411: RabbitMQ amqp091-go client misinterprets oversized strings
CVE-2026-77411 · published 23 days ago
Summary
The RabbitMQ amqp091-go Go client library can read a very large string incorrectly, leaving extra data unread and causing the rest of the communication to become out of sync. This can let a compromised broker disrupt the connection or cause unexpected behavior. Upgrade to version 1.13.0 or later to fix the issue.
What to do
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.5.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.10.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.10.0-root.io.6.
- Update github.com rabbitmq to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version 1.13.0.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.5.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.5.
- Update debian golang-github-rabbitmq-amqp091-go to version 1.14.0-1.
- Update rabbitmq github.com/rabbitmq/amqp091-go to version v1.12.0-aikido.6.
- Update rabbitmq rootio-github.com/rabbitmq/amqp091-go to version v1.12.0-root.io.6.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | rabbitmq | amqp091-go | < 1.13.0 |
| Root:Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< v1.10.0-aikido.5 < v1.10.0-aikido.6 < v1.12.0-aikido.5 < v1.12.0-aikido.6 Fix: upgrade to v1.10.0-aikido.5
|
| Root:Go | rabbitmq | rootio-github.com/rabbitmq/amqp091-go |
< v1.10.0-root.io.5 < v1.10.0-root.io.6 < v1.12.0-root.io.5 < v1.12.0-root.io.6 Fix: upgrade to v1.10.0-root.io.5
|
| go | github.com | rabbitmq |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Go | rabbitmq | github.com/rabbitmq/amqp091-go |
< 1.13.0 Fix: upgrade to 1.13.0
|
| Debian:12 | debian | golang-github-rabbitmq-amqp091-go | All versions |
| Debian:14 | debian | golang-github-rabbitmq-amqp091-go |
< 1.14.0-1 Fix: upgrade to 1.14.0-1
|
Original advisory text
RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.
References
- https://github.com/advisories/GHSA-c5pq-fr2g-9jpf
- https://nvd.nist.gov/vuln/detail/CVE-2026-77411
- https://github.com/rabbitmq/amqp091-go/pull/347
- https://github.com/rabbitmq/amqp091-go Product
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
- https://github.com/rabbitmq/amqp091-go/commit/143c1ace5fa7344cee135e5c7d22970f0d...
- https://security-tracker.debian.org/tracker/CVE-2026-77411 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77411... Vendor Advisory
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-c5pq-fr2g-9jpf
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.5
Critical
Type
CWE-754Improper Check for Unusual or Exceptional Conditions
Timeline
Published16 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-77411 · NVD
CVE-2026-77411 · MITRE
CVE-2026-77411 · OSV
GHSA-c5pq-fr2g-9jpf · GHSA
GHSA-c5pq-fr2g-9jpf · OSV
DEBIAN-CVE-2026-77411 · OSV
GO-2026-6496 · OSV
Track software like this
Free during beta