Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-77405

RabbitMQ amqp091-go client does not set a minimum TLS version for amqps connections

Technology

RabbitMQ

CVSS Score

9.4 / 10.0

Affected Versions

amqp091-go before 1.13.0

Upstream Fix

amqp091-go 1.13.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

tlsConfigFromURI builds tls.Config values without MinVersion set to TLS 1.2. A build on a Go runtime whose default still allows TLS 1.0 or 1.1 can negotiate those versions over an amqps URI, and a network attacker who can influence the negotiation may weaken protection for messages and credentials.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.