CVE-2026-77408
RabbitMQ amqp091-go client silently truncates message properties longer than 255 bytes
Technology
RabbitMQ
CVSS Score
9.1 / 10.0
Affected Versions
amqp091-go before 1.13.0
Upstream Fix
amqp091-go 1.13.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
writeShortstr casts the length of shortstr property values to uint8 without rejecting values over 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding or Type sends a wrapped length and a truncated prefix with no error, which can break request and reply correlation, routing, tracing and downstream processing.
Is your RabbitMQ deployment affected?
If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.