Impact
The vulnerability in the Go AMQP 0.9.1 client allows an attacker to inject characters such as ampersand or equals into a TLS asset path. When the library serializes the URI, it concatenates the CertFile, KeyFile, CACertFile, and ServerName values directly into the query string without URL encoding. If the application later reparses that serialized URI, the injected delimiters break the query string into additional key/value pairs, creating or overwriting connection options. This can corrupt the intended TLS configuration or redirect the client to use unintended local certificate and key files. The impact is that the application might communicate over TLS with an attacker‑controlled or improperly authenticating endpoint, potentially exposing sensitive traffic or facilitating a man‑in‑the‑middle attack. The vulnerability is a CWE-116 (Improper Encoding or Escaping of Characters).
Affected Systems
The issue affects the RabbitMQ amqp091-go client library, specifically all releases prior to version 1.13.0. The library is used by applications that construct a connection URI containing TLS parameters such as CertFile, KeyFile, CACertFile, and ServerName. No specific operating system or platform limitations are listed; the flaw exists wherever the library is linked and used to build or re‑parse connection URIs.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is reported as < 1 % so the likelihood of widespread exploitation is currently low, and it is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted TLS path string that includes special characters and to have that string incorporated into a serialized URI that the application will later parse again. This attack vector is inferred from the description; the CVE does not state an exposed interface, but the vulnerability can be triggered if the application accepts user‑supplied TLS parameters and does not sanitize them before usage.
OpenCVE Enrichment
Github GHSA