CVE-2026-107386
Deferred Deferred - Pending Action

AMQP 0.9.1 Frame Size Bypass in amqp091-go

Vulnerability report for CVE-2026-107386, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rabbitmq amqp091-go >= 1.13.0, < 1.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the amqp091-go library, a Go AMQP 0.9.1 client. It allows a malicious peer to send a frame with a large declared payload length before connection negotiation completes, causing the client to allocate excessive memory before rejecting the frame. This can lead to memory pressure, out-of-memory termination, or process loss before authentication.

Detection Guidance

This vulnerability is specific to the amqp091-go library and requires checking the version of the library in use. Commands like 'go list -m github.com/rabbitmq/amqp091-go' can help identify the installed version. If the version is between 1.13.0 and 1.14.0, the system is potentially vulnerable.

Impact Analysis

If you use the affected versions of amqp091-go (1.13.0 to 1.14.0), a malicious AMQP peer could exploit this to crash your application or consume excessive memory, disrupting service before authentication completes.

Compliance Impact

This vulnerability primarily impacts system availability by enabling memory exhaustion attacks before authentication completes. It does not directly affect confidentiality or integrity of data, which are key concerns for GDPR and HIPAA. However, service disruption from process termination could indirectly impact compliance by failing to maintain availability of systems processing personal or health data.

Mitigation Strategies

Upgrade the amqp091-go library to version 1.14.0 or later immediately. This version includes the fix for the frame-size bypass issue. If upgrading is not possible, consider disabling AMQP connections until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107386. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart