CVE-2026-77410: RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation
**Summary** A flaw in the `recvContent` function allows a malicious AMQP server to trigger an Out-of-Memory (OOM) error, forcing the host operating system or container runtime to immediately terminate the client process. **Vulnerability Details** When receiving message content payloads, the client processes the expected size from the content header framework. The `recvContent` function attempts to optimize performance by pre-allocating memory for the message body based on the `ch.header.Size` field, which is a 64-bit unsigned integer (`uint64`). ```go // channel.go:495-496 if cap(ch.body) == 0 { ch.body = make([]byte, 0, ch.header.Size) // unbounded } ``` The underlying library fails to validate or cap this requested size against any upper boundary—such as the maximum frame size negotiated during connection establishment (`FrameMax`). If a server specifies an extreme body size (e.g., `2^62` bytes), the Go runtime attempts to allocate an exabyte-scale slice capacity. This immediately exhausts available system memory, causing the operating system's OOM killer to terminate the application. **Attack Vector / Exploitation Scenario** - Message Delivery Phase: A malicious or compromised AMQP broker sends a standard `basic.deliver` frame containing a content header with an intentionally inflated `body-size` variable. - Authentication Requirement: No special privileges or authentication bypasses are required; the crash occurs seamlessly during normal message consumption. **Impact** - Availability: High. Exploded memory consumption results in an instant process termination, destroying application state and availability for all threads sharing the environment.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/rabbitmq/amqp091-go 1.13.0.
Technical details
- Vendor
- Not specified
- Product
- github.com/rabbitmq/amqp091-go
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source