← All Advisories

CVE-2026-77403

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-77403

Key Details

CVECVE-2026-77403
CVSS Score / Version8.9 (High) / CVSS v4.0
Updated2026-09-23
Affected productsrabbitmq amqp091-go
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
rabbitmqamqp091-go
SubsystemsGeneral OT
SectorsMultiple

What to Know

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0. (NVD)

What to Do

Monitor rabbitmq's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-77403
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-77403