Back

HIGH

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation

Published Sep 16, 2026

Description

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 16, 2026
Updated Sep 16, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 16, 2026
NVD
Status Received
Modified Sep 16, 2026
Red Hat
Severity Moderate
Public date Sep 16, 2026
ENISA EUVD
Assigner GitHub_M
Published Sep 16, 2026
Updated Sep 16, 2026
Exploited since n/a
EUVD-2026-80807 GHSA-XWWF-M8FG-P9Q2