Impact
A Go AMQP 0.9.1 client library implements a function that reads a long string value from a broker. When the length field is larger than the maximum signed 32‑bit value, the function incorrectly returns an empty string and no error while leaving unconsumed bytes in the stream. The subsequent table parsing routine assumes the read completed successfully, causing the reader to misinterpret the remaining bytes as frame data. The result is a desynchronised protocol state, allowing attacker‑controlled bytes to be interpreted as legitimate AMQP frames or fields, which can break connection integrity and result in denial of service.
Affected Systems
All installations of the RabbitMQ amqp091-go client library earlier than version 1.13.0 are vulnerable. This library is typically embedded in Go applications that communicate with RabbitMQ brokers over AMQP 0.9.1. Any application using an older version of the library is impacted, regardless of its operating system or deployment environment.
Risk and Exploitability
The vulnerability scores a CVSS of 9.5, indicating high severity. Its EPSS score of less than 1% suggests the exploitation probability is low, but that does not diminish the risk of a trusted broker providing a crafted oversized long string. The exploit requires control over the broker’s messaging, which may be feasible for an attacker who compromises or controls a broker or creates a malicious broker to serve clients. The exploit is straightforward for a broker attacker; the library will fail to detect the malformed frame, and the client connection will become unreliable or drop, potentially causing service disruption. The vulnerability is not listed in the CISA KEV catalog currently, but the impact to availability makes it a strong candidate for immediate remediation.
OpenCVE Enrichment
Github GHSA