OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-77412: RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client

GitHub Advisories · officialPublished Sep 17, 2026Risk 37/100

**Summary** A vulnerability in the readField function allows a malicious or compromised AMQP server to trigger an unhandled runtime panic in the client application, leading to an immediate crash of the entire process. **Details** When parsing incoming AMQP frames, the `readField` function processes byte-array fields (type tag `'x'`) by reading a 32-bit big-endian integer to determine the length of the data payload. ```go // read.go:253-263 case 'x': var len int32 if err = binary.Read(r, binary.BigEndian, &len); err != nil { return nil, err } value := make([]byte, len) // PANICS if len < 0 ``` If a server transmits a length value of `0xFFFFFFFF`, it is interpreted by the client as a signed 32-bit integer with a value of `-1`. Passing a negative integer to Go's built-in make() function for slice allocation triggers an unrecoverable runtime panic (panic: len out of range). Because the reader goroutine handles network I/O without an explicit recover() wrapper, this panic propagates up to the runtime root, abruptly terminating the host application. **Attack Vector / Exploitation Scenario** An attacker capable of spoofing, compromising, or controlling an AMQP broker can exploit this flaw during two primary phases: 1. Connection Establishment: Sending a malicious connection.start handshake frame containing server-properties with an 'x' type field assigned a negative length. 2. Message Delivery: Delivering a message payload where the header table contains a malformed field matching the criteria above. **Impact** Availability: High. A single malformed frame can reliably crash the client process, resulting in a persistent Denial of Service (DoS) if the client automatically reconnects and receives the same payload.

Upgrade affected packages to a patched version: github.com/rabbitmq/amqp091-go 1.13.0.

Vendor
Not specified
Product
github.com/rabbitmq/amqp091-go
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source