amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Sat, 29 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rabbitmq
Rabbitmq amqp091-go |
|
| Vendors & Products |
Rabbitmq
Rabbitmq amqp091-go |
Wed, 26 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available. | |
| Title | amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-08-26T20:24:58.115Z
Updated: 2026-08-29T02:50:25.822Z
Reserved: 2026-08-25T14:59:32.746Z
Link: CVE-2026-79921
Updated: 2026-08-29T02:50:21.348Z
Status : Received
Published: 2026-08-26T21:16:41.873
Modified: 2026-08-29T03:17:10.490
Link: CVE-2026-79921
No data.