Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, consumer cancellations, returned messages, including NotifyConfirm events and connection block notifications, to application-provided channels. If a listener channel is unbuffered, full, or not drained promptly, the sole reader goroutine blocks and stops processing frames, acknowledgments, deliveries, and heartbeats. Broker-driven event bursts can therefore cause connection stalls, missed heartbeats, deadlocks, and disconnection. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The malicious or misconfigured publisher can send a burst of synchronous events to a client that uses unbuffered or poorly drained notification channels. Each event blocks a single goroutine that also processes frames, acknowledgments, deliveries, and heartbeats. The blocking of this goroutine prevents the library from consuming further frames or sending heartbeats, thereby causing connection stalls, missed heartbeats, and eventually disconnection. The issue can also deadlock the application if the single goroutine never resumes. This is a classic resource exhaustion flaw classified as CWE-770.

Affected Systems

RabbitMQ amqp091-go, a Go AMQP 0.9.1 client library. The vulnerability exists in all releases older than v1.13.0; users of any version before 1.13.0 are affected.

Risk and Exploitability

The CVSS score of 8.2 indicates a high-severity denial-of-service. The EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not yet listed in CISA KEV. Because the attack relies on broker‐driven event bursts to a consumer using unbuffered channels, an attacker would need to generate such traffic from the broker side or influence the client’s event handling logic. Thus, the risk is moderate to high severity but the likelihood of a real‑world exploit is low at present.

Generated by OpenCVE AI on September 18, 2026 at 02:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade RabbitMQ amqp091-go to v1.13.0 or later.
  • Modify application code to drain event channels rapidly or use sufficiently buffered channels for publisher confirmations and flow‑control events.
  • Monitor AMQP connections for stalled goroutines, missing heartbeats, and disconnections, and trigger alerts if these conditions arise.

Generated by OpenCVE AI on September 18, 2026 at 02:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, consumer cancellations, returned messages, including NotifyConfirm events and connection block notifications, to application-provided channels. If a listener channel is unbuffered, full, or not drained promptly, the sole reader goroutine blocks and stops processing frames, acknowledgments, deliveries, and heartbeats. Broker-driven event bursts can therefore cause connection stalls, missed heartbeats, deadlocks, and disconnection. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:03:12.744Z

Reserved: 2026-08-20T19:55:27.024Z

Link: CVE-2026-77409

cve-icon Vulnrichment

Updated: 2026-09-18T18:03:07.931Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:50.293

Modified: 2026-09-24T21:16:28.120

Link: CVE-2026-77409

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:48:00Z

Links: CVE-2026-77409 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling