Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Metadata Corruption and Service Disruption
Action: Immediate Patch
AI Analysis

Impact

The RabbitMQ amqp091-go client contained an integer overflow in the writeShortstr function: the byte length of AMQP shortstring properties was cast to a uint8 without first rejecting values larger than 255 bytes. When an application supplied an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value, the library serialized a truncated prefix while reporting the full length. This silent truncation corrupts the metadata that drives request and reply correlation, routing logic, tracing, and downstream message processing, an issue identified as CWE‑190.

Affected Systems

Any application using the RabbitMQ amqp091-go Go AMQP 0.9.1 client library version 1.12.x or earlier is affected. The vulnerability is fixed in release 1.13.0, so only rabbitmq:amqp091-go is impacted. No specific RabbitMQ server versions are required to be mitigated; the issue resides solely in the client library.

Risk and Exploitability

The CVSS score of 9.1 indicates a high‑severity vulnerability with integrity and availability impact. The EPSS score of <1% suggests that real‑world exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the overflow occurs during message serialization, an attacker who can inject or alter AMQP messages sent to a client using the vulnerable library can induce silent metadata corruption. The absence of an explicit error response allows the attacker to operate stealthily, making detection more difficult. The primary attack surface involves sending malformed AMQP messages from the network or a compromised application that uses the library.

Generated by OpenCVE AI on September 18, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the RabbitMQ amqp091-go client library to version 1.13.0 or later to eliminate the overflow condition.
  • Implement application‑level validation to reject or truncate CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type values that exceed 255 characters before passing them to the library.
  • Monitor broker and application logs for correlation failures, unexpected routing drops, or message truncation anomalies as an early detection measure.

Generated by OpenCVE AI on September 18, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j497-x9hr-x34x RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
Weaknesses CWE-190
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:L'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:01:27.706Z

Reserved: 2026-08-20T19:55:27.023Z

Link: CVE-2026-77408

cve-icon Vulnrichment

Updated: 2026-09-16T15:01:23.341Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:49.747

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-77408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:00:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound