← All Advisories

CVE-2026-77408

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-77408

Key Details

CVECVE-2026-77408
CVSS Score / Version9.1 (Critical) / CVSS v4.0
Updated2026-09-23
Affected productsrabbitmq amqp091-go
Classified asCWE-190 (Integer Overflow or Wraparound)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
rabbitmqamqp091-go
SubsystemsGeneral OT
SectorsMultiple

What to Know

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0. (NVD)

What to Do

Monitor rabbitmq's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-77408
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-77408