Impact
RabbitMQ amqp091-go, a Go client for the AMQP 0.9.1 protocol, preallocates a byte slice for a message body based on the size declared in an AMQP content header. Because no cap is applied against the negotiated frame size, a broker that supplies an excessively large body size can force the Go runtime to allocate a huge buffer before any data is received. This unbounded memory allocation (CWE‑789) can exhaust available memory and terminate the client process, effectively denying service to the application.
Affected Systems
The vulnerability affects the RabbitMQ amqp091-go client library version 1.13.0 and earlier. Any Go application that imports the amqp091-go package and establishes AMQP connections to a broker may be impacted if the broker is malicious or compromised.
Risk and Exploitability
The risk profile is high, with a CVSS base score of 8.9 and an EPSS score of less than 1%, indicating very low current exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires control over or compromise of the broker to send a deliberately oversized message. Successful exploitation leads to client process termination and service disruption. There is no public exploit known, but the combination of high impact and non‑zero EPSS warrants timely remediation.
OpenCVE Enrichment
Github GHSA