Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-77411
RabbitMQ amqp091-go client keeps parsing from the wrong offset after an oversized longstr
Technology
RabbitMQ
CVSS Score
9.5 / 10.0
Affected Versions
amqp091-go before 1.13.0
Upstream Fix
amqp091-go 1.13.0
Published
September 16, 2026
OSSeva Coverage
Fixed upstream
Description
readLongstr returns an empty string and no error when a declared AMQP longstr length exceeds 0x7FFFFFFF, and leaves the field bytes unread. readTable carries on from the wrong offset, so a malicious or compromised broker can make trailing bytes it controls be read as later fields or frames, breaking connection integrity and availability.
Is your RabbitMQ deployment affected?
If you're running amqp091-go before 1.13.0, you need this patch. Book a discovery call to get covered.