Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-77411

RabbitMQ amqp091-go client keeps parsing from the wrong offset after an oversized longstr

Technology

RabbitMQ

CVSS Score

9.5 / 10.0

Affected Versions

amqp091-go before 1.13.0

Upstream Fix

amqp091-go 1.13.0

Published

September 16, 2026

OSSeva Coverage

Fixed upstream

Description

readLongstr returns an empty string and no error when a declared AMQP longstr length exceeds 0x7FFFFFFF, and leaves the field bytes unread. readTable carries on from the wrong offset, so a malicious or compromised broker can make trailing bytes it controls be read as later fields or frames, breaking connection integrity and availability.

Upstream record: NVD · CVE.org

Is your RabbitMQ deployment affected?

If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.