Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-77408

RabbitMQ amqp091-go client silently truncates message properties longer than 255 bytes

Technology

RabbitMQ

CVSS Score

9.1 / 10.0

Affected Versions

amqp091-go before 1.13.0

Upstream Fix

amqp091-go 1.13.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

writeShortstr casts the length of shortstr property values to uint8 without rejecting values over 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding or Type sends a wrapped length and a truncated prefix with no error, which can break request and reply correlation, routing, tracing and downstream processing.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.