Impact
The RabbitMQ amqp091-go client contained an integer overflow in the writeShortstr function: the byte length of AMQP shortstring properties was cast to a uint8 without first rejecting values larger than 255 bytes. When an application supplied an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value, the library serialized a truncated prefix while reporting the full length. This silent truncation corrupts the metadata that drives request and reply correlation, routing logic, tracing, and downstream message processing, an issue identified as CWE‑190.
Affected Systems
Any application using the RabbitMQ amqp091-go Go AMQP 0.9.1 client library version 1.12.x or earlier is affected. The vulnerability is fixed in release 1.13.0, so only rabbitmq:amqp091-go is impacted. No specific RabbitMQ server versions are required to be mitigated; the issue resides solely in the client library.
Risk and Exploitability
The CVSS score of 9.1 indicates a high‑severity vulnerability with integrity and availability impact. The EPSS score of <1% suggests that real‑world exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the overflow occurs during message serialization, an attacker who can inject or alter AMQP messages sent to a client using the vulnerable library can induce silent metadata corruption. The absence of an explicit error response allows the attacker to operate stealthily, making detection more difficult. The primary attack surface involves sending malformed AMQP messages from the network or a compromised application that uses the library.
OpenCVE Enrichment
Github GHSA