Impact
The vulnerability in RabbitMQ amqp091-go arises from the way the client parses an AMQP byte-array field. When the broker supplies a field length encoded as 0xFFFFFFFF, the library interprets it as a signed 32‑bit integer, yielding -1. This negative size is then passed to "make" to allocate a buffer, causing a length‐out‑of‑range runtime panic. The panic propagates out of the network reader goroutine and terminates the entire client process. Consequently, an attacker can force the client to crash, disrupting messaging operations without exploiting memory corruption or executing arbitrary code. The weakness maps to CWE‑681 (Conversion between numeric types that alters meaning) and CWE‑805 (Buffer Access with Incorrect Length Value).
Affected Systems
This defect affects any deployment using the RabbitMQ amqp091-go client library before version 1.13.0. The library is intended for use in Go applications that communicate with AMQP 0.9.1 brokers, such as RabbitMQ. Organizations that integrate the client into microservices or message‑driven architectures are directly impacted if they have not upgraded to a patched release.
Risk and Exploitability
With a CVSS score of 8.9, the vulnerability provides a high impact denial of service to the affected client. The EPSS score of less than 1% indicates that, at the time of this assessment, exploitation is considered unlikely but not impossible, often requiring a broker under the attacker’s control. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve a malicious or compromised broker that sends specially crafted frame lengths to the client; the exploit requires only network connectivity to the client, making it a remote vulnerability exploitable by anyone who can influence broker responses.
OpenCVE Enrichment
Github GHSA