Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation to the negotiated Connection.Config.FrameSize value. A malicious or compromised broker can send an extreme declared body size and cause the Go runtime to attempt a correspondingly large allocation before body data is received. The allocation can exhaust memory and terminate the client process. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

RabbitMQ amqp091-go, a Go client for the AMQP 0.9.1 protocol, preallocates a byte slice for a message body based on the size declared in an AMQP content header. Because no cap is applied against the negotiated frame size, a broker that supplies an excessively large body size can force the Go runtime to allocate a huge buffer before any data is received. This unbounded memory allocation (CWE‑789) can exhaust available memory and terminate the client process, effectively denying service to the application.

Affected Systems

The vulnerability affects the RabbitMQ amqp091-go client library version 1.13.0 and earlier. Any Go application that imports the amqp091-go package and establishes AMQP connections to a broker may be impacted if the broker is malicious or compromised.

Risk and Exploitability

The risk profile is high, with a CVSS base score of 8.9 and an EPSS score of less than 1%, indicating very low current exploit probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires control over or compromise of the broker to send a deliberately oversized message. Successful exploitation leads to client process termination and service disruption. There is no public exploit known, but the combination of high impact and non‑zero EPSS warrants timely remediation.

Generated by OpenCVE AI on September 18, 2026 at 02:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the amqp091-go library to version 1.13.0 or newer to apply the allocation bounds fix.
  • If an upgrade cannot be performed immediately, isolate the application from untrusted brokers or configure the broker to refuse messages with body sizes exceeding a safe threshold.
  • Implement a process supervisor or restart mechanism to recover the client automatically after a crash, and monitor memory usage to detect anomalous spikes.

Generated by OpenCVE AI on September 18, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r9c8-gcjp-xfwh RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation to the negotiated Connection.Config.FrameSize value. A malicious or compromised broker can send an extreme declared body size and cause the Go runtime to attempt a correspondingly large allocation before body data is received. The allocation can exhaust memory and terminate the client process. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
Weaknesses CWE-789
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:41:15.593Z

Reserved: 2026-08-20T19:55:27.024Z

Link: CVE-2026-77410

cve-icon Vulnrichment

Updated: 2026-09-16T15:41:07.923Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:50.430

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-77410

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:39:08Z

Links: CVE-2026-77410 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value