Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-77405
RabbitMQ amqp091-go client does not set a minimum TLS version for amqps connections
Technology
RabbitMQ
CVSS Score
9.4 / 10.0
Affected Versions
amqp091-go before 1.13.0
Upstream Fix
amqp091-go 1.13.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
tlsConfigFromURI builds tls.Config values without MinVersion set to TLS 1.2. A build on a Go runtime whose default still allows TLS 1.0 or 1.1 can negotiate those versions over an amqps URI, and a network attacker who can influence the negotiation may weaken protection for messages and credentials.
Is your RabbitMQ deployment affected?
If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.