Impact
Prior to version 1.13.0, the RabbitMQ Go AMQP 0.9.1 client accepted a server‑advertised FrameMax lower than the protocol‑required minimum of 4096 bytes. This loophole allowed an adversarial or compromised broker to perform frame size negotiation that fragmented client messages into an excessive number of frames, leading to high CPU usage and potential stalls for the client and the host. The flaw is a classic resource exhaustion vulnerability, classified under CWE‑770.
Affected Systems
The issue affects the RabbitMQ Go AMQP 0.9.1 client library, commonly referenced as rabbitmq:amqp091-go. Any Go application that imports and uses this library in a version earlier than 1.13.0 is potentially affected. There is no specific product line beyond the client library itself, but the vulnerability surfaces in any environment where the library communicates with an AMQP broker.
Risk and Exploitability
The CVSS score is 8.9, indicating a high severity impact. The EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA's KEV catalog, but a malicious or compromised broker can trivially request a very small FrameMax during connection negotiation. By doing so, an attacker can force the client to perform numerous write operations, exhausting CPU resources and potentially causing a denial of service. The attack requires communication with the broker; therefore, remote exploitation is possible when an attacker controls or compromises an AMQP broker that clients connect to.
OpenCVE Enrichment
Github GHSA