Back

HIGH

RabbitMQ amqp091-go: Denial of Service via Synchronous Event Channel Blocking

Published Sep 16, 2026

Description

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, consumer cancellations, returned messages, including NotifyConfirm events and connection block notifications, to application-provided channels. If a listener channel is unbuffered, full, or not drained promptly, the sole reader goroutine blocks and stops processing frames, acknowledgments, deliveries, and heartbeats. Broker-driven event bursts can therefore cause connection stalls, missed heartbeats, deadlocks, and disconnection. This issue is fixed in version 1.13.0.

Affected products

Remediation

Red Hat statement

This flaw has an Important impact because a broker-driven event burst can block AMQP client processing when application notification channels are unbuffered, full, or not promptly drained. The resulting stall can cause missed heartbeats, deadlocks, or client disconnection.

Red Hat mitigation

Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 16, 2026
Updated Sep 18, 2026
Reserved Aug 20, 2026
CISA Vulnrichment
Updated Sep 18, 2026
NVD
Status Received
Modified Sep 18, 2026
Red Hat
Severity Important
Public date Sep 16, 2026
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a