Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-44236

rabbitmq-c heap overflow from an undersized frame_max during login

Technology

RabbitMQ

CVSS Score

7.1 / 10.0

Affected Versions

rabbitmq-c before 0.16.0

Upstream Fix

rabbitmq-c 0.16.0

Published

September 17, 2026

OSSeva Coverage

Fixed upstream

Description

rabbitmq-c accepts a server-sent connection.tune frame_max below the AMQP minimum and resizes its outbound buffer to it, then writes connection.tune-ok past the end of that buffer. A malicious server, or an on-path attacker on plaintext AMQP, can corrupt client memory and most likely crash it; code execution was not demonstrated.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running rabbitmq-c before 0.16.0, you need this patch. Book a discovery call to get covered.