Description
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed per-frame fields, and FOOTER_SIZE from state->target_size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp_decode_properties() to amqp_decode_table_internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or code execution shown. This issue is fixed in version 0.16.0.
Published: 2026-09-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A malicious AMQP server can send an undersized HEADER or METHOD frame during client login, causing an unsigned size_t underflow in rabbitmq-c’s amqp_handle_input() function. The parser subtracts the fixed frame header and footer sizes from the target size without verifying the minimum frame length, leading to an out‑of‑bounds read in amqp_decode_table_internal(). The resulting process crash manifests as a denial of service. No reliable memory disclosure or code execution has been demonstrated, so the impact is limited to service interruption.

Affected Systems

The vulnerability exists in versions of the rabbitmq-c client library before v0.16.0 distributed by alanxz. All releases prior to v0.16.0 are affected, and the issue is fixed in v0.16.0.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker on the network path can trigger the denial of service by sending a specially crafted undersized frame to a client that is connecting or already authenticated, provided the AMQP traffic is not protected by TLS with proper certificate validation. No additional privileged access on the client side is required.

Generated by OpenCVE AI on September 19, 2026 at 03:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the rabbitmq-c client library to version 0.16.0 or later to eliminate the undersized frame handling flaw.
  • Configure all AMQP connections to use TLS with certificate validation so that traffic is encrypted and the vulnerable client will not accept malformed frames from untrusted sources.
  • If an upgrade is not immediately feasible, isolate the affected clients from untrusted networks, monitor for abnormal crashes, and limit the set of servers that can be contacted by the clients.

Generated by OpenCVE AI on September 19, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4658-1 librabbitmq security update
Debian DSA Debian DSA DSA-6343-1 librabbitmq security update
Ubuntu USN Ubuntu USN USN-8437-1 rabbitmq-c vulnerabilities
Ubuntu USN Ubuntu USN USN-8724-1 rabbitmq-c vulnerabilities
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Alanxz
Alanxz rabbitmq-c
Vendors & Products Alanxz
Alanxz rabbitmq-c

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabbitmq/amqp_connection.c. The parser subtracts HEADER_SIZE, fixed per-frame fields, and FOOTER_SIZE from state->target_size without first checking the minimum frame length. The wrapped encoded.len value is passed through amqp_decode_properties() to amqp_decode_table_internal(), where it defeats bounds checks and causes an out-of-bounds read and process crash. An on-path attacker can also trigger the issue when AMQP traffic is not protected by TLS with certificate validation. The demonstrated impact is denial of service, with no reliable memory disclosure or code execution shown. This issue is fixed in version 0.16.0.
Title rabbitmq-c: size_t underflow in AMQP frame length computation leads to out-of-bounds read
Weaknesses CWE-125
CWE-191
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Alanxz Rabbitmq-c
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:43:19.821Z

Reserved: 2026-05-05T15:42:40.519Z

Link: CVE-2026-44235

cve-icon Vulnrichment

Updated: 2026-09-17T17:43:16.469Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T18:16:43.850

Modified: 2026-09-30T17:43:24.057

Link: CVE-2026-44235

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T17:09:48Z

Links: CVE-2026-44235 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:15:16Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-191

    Integer Underflow (Wrap or Wraparound)