Impact
RabbitMQ amqp091-go improperly casts negative prefetchCount and prefetchSize values to unsigned integers, allowing values such as -1 to wrap around to 65535 or 4294967295. An application that accepts untrusted QoS configuration can thus request extremely large prefetch limits, causing the broker to deliver a vast number of queued messages. This overload exhausts the client’s memory and disrupts its processing, effectively denying service to the impacted process.
Affected Systems
The vulnerability is present in the Go AMQP 0.9.1 client library rabbitmq:amqp091-go for all releases prior to version 1.13.0. Any application using those older releases and allowing external configuration of QoS parameters is affected.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply or influence the QoS prefetch values; once negative values are accepted, the broker will deliver a large number of messages leading to memory exhaustion. The attack vector is therefore application–level configuration rather than a remote network exploit.
OpenCVE Enrichment
Github GHSA