RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation
Published Sep 16, 2026
8.9
HIGHCVSS 4.0
EPSS 0.52%
Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.
Affected products
-
- Version < 1.13.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rabbitmq | Amqp091-GO | n/a |
|
No data.
No data.
Red Hat Hardened Images
opentelemetry-collector-contrib-main-0.161.0-0.1.hum1
Fixed · RHSA-2026:68290
Cryostat 4
cryostat/cryostat-storage-rhel9
Affected
Custom Metric Autoscaler operator for Red Hat Openshift
custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9
Affected
Custom Metric Autoscaler operator for Red Hat Openshift
custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9
Not affected
Custom Metric Autoscaler operator for Red Hat Openshift
custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9
Affected
Custom Metric Autoscaler operator for Red Hat Openshift
custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator
Not affected
Multicluster Global Hub
multicluster-globalhub/multicluster-globalhub-grafana-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-plugin-event-sender-rhel9
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel9
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-operator-bundle
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-rhel9
Not affected
Red Hat OpenStack Platform 18.0
rhoso-operators/rabbitmq-cluster-rhel9-operator
Affected
Red Hat Quay 3
quay/clair-rhel8
Affected
Red Hat Quay 3
quay/clair-rhel9
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | opentelemetry-collector-contrib-main-0.161.0-0.1.hum1 | Fixed | RHSA-2026:68290 |
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Affected | n/a |
| Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9 | Affected | n/a |
| Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9 | Not affected | n/a |
| Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9 | Affected | n/a |
| Custom Metric Autoscaler operator for Red Hat Openshift | custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator | Not affected | n/a |
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-plugin-event-sender-rhel9 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-operator-bundle | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Not affected | n/a |
| Red Hat OpenStack Platform 18.0 | rhoso-operators/rabbitmq-cluster-rhel9-operator | Affected | n/a |
| Red Hat Quay 3 | quay/clair-rhel8 | Affected | n/a |
| Red Hat Quay 3 | quay/clair-rhel9 | Affected | n/a |
github.com/rabbitmq/amqp091-go
Go
Introduced 0 Fixed 1.13.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/rabbitmq/amqp091-go | 0 | 1.13.0 |
Remediation
Red Hat mitigation
To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation.
References (10)
- https://access.redhat.com/security/cve/CVE-2026-77403 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2535498 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-80807 Advisory
- https://github.com/advisories/GHSA-xwwf-m8fg-p9q2 Advisory
- https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06 x_refsource_MISC
- https://github.com/rabbitmq/amqp091-go/pull/353 x_refsource_MISC
- https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 x_refsource_MISC
- https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-77403
- https://www.cve.org/CVERecord?id=CVE-2026-77403
Change history (0)
No recorded changes yet.