Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rabbitmq
Rabbitmq amqp091-go |
|
| Vendors & Products |
Rabbitmq
Rabbitmq amqp091-go |
Wed, 16 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0. | |
| Title | RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-16T15:43:19.632Z
Reserved: 2026-08-20T19:55:27.023Z
Link: CVE-2026-77403
Updated: 2026-09-16T15:43:14.111Z
Status : Received
Published: 2026-09-16T15:17:46.847
Modified: 2026-09-16T16:17:15.633
Link: CVE-2026-77403
No data.
OpenCVE Enrichment
Updated: 2026-09-16T16:30:07Z