Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Weak Transport Encryption
Action: Patch
AI Analysis

Impact

A vulnerability in the RabbitMQ amqp091-go client causes TLS configurations created from URI parsing to omit a minimum protocol version constraint, allowing the use of TLS 1.0 or TLS 1.1. In environments where the Go runtime defaults to accept these legacy protocols, an attacker able to influence TLS negotiation could force the client to use an obsolete protocol, thereby weakening the encryption protecting AMQP messages and credentials. The weakness can lead to loss of confidentiality of data in transit, and potentially compromise credentials used for authentication. The flaw is classified under CWE‑326, highlighting improper validation of cryptographic strength.

Affected Systems

RabbitMQ amqp091-go implementations built with Go runtimes that permit TLS 1.0 or TLS 1.1, specifically versions prior to 1.13.0. The issue is fixed in release 1.13.0 and later, which sets the minimum TLS version to 1.2 in the configuration produced by tlsConfigFromURI.

Risk and Exploitability

The CVSS score of 9.4 marks the vulnerability as critical severity, while the EPSS score of fewer than 1% indicates a very low probability of exploitation at the current time. The vulnerability is not present in the CISA KEV catalog. An attacker would need network access to influence TLS negotiation between a client using the affected library and a server, which is likely feasible in many networked deployments. The lack of a minimum TLS version permits downgrade attacks that could expose sensitive AMQP traffic.

Generated by OpenCVE AI on September 18, 2026 at 02:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade RabbitMQ amqp091-go to version 1.13.0 or later, which sets the TLS minimum version to 1.2 during URI parsing.
  • Verify that the Go runtime used by the application does not allow TLS 1.0 or TLS 1.1 by default; enforce TLS 1.2 or higher in the runtime configuration if possible.
  • If immediate upgrade is not feasible, consider applying the patch commit c9fd433e that adds MinVersion TLS1.2 to tls.Config, ensuring legacy protocols are rejected during negotiation.

Generated by OpenCVE AI on September 18, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-33mj-cw25-m34h RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser
Weaknesses CWE-326
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:L/SA:N'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:59:20.584Z

Reserved: 2026-08-20T19:55:27.023Z

Link: CVE-2026-77405

cve-icon Vulnrichment

Updated: 2026-09-18T17:59:15.749Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:47.980

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-77405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength