Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.
Published: 2026-09-16
Score: 9.5 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Desynchronization and Frame Injection
Action: Patch Immediately
AI Analysis

Impact

A Go AMQP 0.9.1 client library implements a function that reads a long string value from a broker. When the length field is larger than the maximum signed 32‑bit value, the function incorrectly returns an empty string and no error while leaving unconsumed bytes in the stream. The subsequent table parsing routine assumes the read completed successfully, causing the reader to misinterpret the remaining bytes as frame data. The result is a desynchronised protocol state, allowing attacker‑controlled bytes to be interpreted as legitimate AMQP frames or fields, which can break connection integrity and result in denial of service.

Affected Systems

All installations of the RabbitMQ amqp091-go client library earlier than version 1.13.0 are vulnerable. This library is typically embedded in Go applications that communicate with RabbitMQ brokers over AMQP 0.9.1. Any application using an older version of the library is impacted, regardless of its operating system or deployment environment.

Risk and Exploitability

The vulnerability scores a CVSS of 9.5, indicating high severity. Its EPSS score of less than 1% suggests the exploitation probability is low, but that does not diminish the risk of a trusted broker providing a crafted oversized long string. The exploit requires control over the broker’s messaging, which may be feasible for an attacker who compromises or controls a broker or creates a malicious broker to serve clients. The exploit is straightforward for a broker attacker; the library will fail to detect the malformed frame, and the client connection will become unreliable or drop, potentially causing service disruption. The vulnerability is not listed in the CISA KEV catalog currently, but the impact to availability makes it a strong candidate for immediate remediation.

Generated by OpenCVE AI on September 18, 2026 at 02:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the amqp091-go library to version 1.13.0 or newer to replace the faulty readLongstr implementation.
  • Recompile dependent applications to link against the updated library and restart the services.
  • If an upgrade cannot be applied immediately, restrict connections to trusted, authenticated brokers and monitor for malformed or oversized frames that could indicate protocol manipulation.

Generated by OpenCVE AI on September 18, 2026 at 02:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-c5pq-fr2g-9jpf RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
History

Fri, 18 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Rabbitmq
Rabbitmq amqp091-go
Vendors & Products Rabbitmq
Rabbitmq amqp091-go

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.
Title RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr
Weaknesses CWE-754
References
Metrics cvssV4_0

{'score': 9.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Rabbitmq Amqp091-go
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T18:35:32.972Z

Reserved: 2026-08-20T19:55:27.024Z

Link: CVE-2026-77411

cve-icon Vulnrichment

Updated: 2026-09-16T18:23:23.202Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:50.563

Modified: 2026-09-23T18:19:19.803

Link: CVE-2026-77411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T05:00:03Z

Weaknesses
  • CWE-754

    Improper Check for Unusual or Exceptional Conditions