Impact
The malicious or misconfigured publisher can send a burst of synchronous events to a client that uses unbuffered or poorly drained notification channels. Each event blocks a single goroutine that also processes frames, acknowledgments, deliveries, and heartbeats. The blocking of this goroutine prevents the library from consuming further frames or sending heartbeats, thereby causing connection stalls, missed heartbeats, and eventually disconnection. The issue can also deadlock the application if the single goroutine never resumes. This is a classic resource exhaustion flaw classified as CWE-770.
Affected Systems
RabbitMQ amqp091-go, a Go AMQP 0.9.1 client library. The vulnerability exists in all releases older than v1.13.0; users of any version before 1.13.0 are affected.
Risk and Exploitability
The CVSS score of 8.2 indicates a high-severity denial-of-service. The EPSS score of less than 1% signals a low probability of exploitation in the wild. The vulnerability is not yet listed in CISA KEV. Because the attack relies on broker‐driven event bursts to a consumer using unbuffered channels, an attacker would need to generate such traffic from the broker side or influence the client’s event handling logic. Thus, the risk is moderate to high severity but the likelihood of a real‑world exploit is low at present.
OpenCVE Enrichment