Description
rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.
Published: 2026-09-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

rabbitmq-c, a C-language AMQP client library, has a heap buffer overflow in the AMQP login handshake. During amqp_login(), an attacker can send an undersized connection.tune.frame_max value. The library accepts this value and later reallocates the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. When the connection.tune-ok frame is serialized, the client writes beyond the undersized heap allocation, corrupting memory. This leads to a denial of service and could potentially allow code execution, although no exploit has been demonstrated.

Affected Systems

The vulnerability affects the rabbitmq-c library produced by alanxz. All releases older than 0.16.0 are vulnerable. The fix is included in version 0.16.0; upgrading eliminates the overflow. No specific operating system or distribution is mentioned in the data, so any platform using the affected library is at risk.

Risk and Exploitability

The CVSS score of 7.1 marks the issue as high severity, and the EPSS score of less than 1% implies a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring a client to initiate a connection with a malicious or compromised AMQP server. For plaintext AMQP traffic, an on-path attacker could trigger the flaw. Successful exploitation would result in memory corruption and likely a service crash; theoretical code execution could occur if the client runs with elevated privileges. Given the high CVSS and the lack of a public exploit, timely patching is advised.

Generated by OpenCVE AI on September 23, 2026 at 01:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rabbitmq-c to version 0.16.0 or later to apply the heap buffer overflow fix.
  • Restrict outbound AMQP connections to known, trusted servers to reduce exposure to malicious handshake messages.
  • Use TLS for AMQP traffic or configure firewalls to block unauthenticated or untrusted AMQP servers, limiting the attack surface.

Generated by OpenCVE AI on September 23, 2026 at 01:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4658-1 librabbitmq security update
Debian DSA Debian DSA DSA-6343-1 librabbitmq security update
Ubuntu USN Ubuntu USN USN-8437-1 rabbitmq-c vulnerabilities
Ubuntu USN Ubuntu USN USN-8724-1 rabbitmq-c vulnerabilities
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-131
References
Metrics threat_severity

None

threat_severity

Important


Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Alanxz
Alanxz rabbitmq-c
Vendors & Products Alanxz
Alanxz rabbitmq-c

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.
Title rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Alanxz Rabbitmq-c
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:59:56.472Z

Reserved: 2026-05-05T15:42:40.519Z

Link: CVE-2026-44236

cve-icon Vulnrichment

Updated: 2026-09-21T20:59:45.493Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T18:16:44.503

Modified: 2026-09-24T15:02:58.307

Link: CVE-2026-44236

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-17T17:04:18Z

Links: CVE-2026-44236 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:00:10Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-131

    Incorrect Calculation of Buffer Size