CVE-2026-77408: RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow
## Summary A data integrity and protocol corruption vulnerability exists in the AMQP client's property serialization logic. When encoding AMQP short string (`shortstr`) fields—such as identifiers, routing strings, and content metadata—the length of the string is explicitly cast to a fixed-size 8-bit unsigned integer (`uint8`). If an application provides a property string exceeding 255 bytes, the length counter silently wraps around (e.g., a length of 300 wraps to 44). As a result, the parser writes only a truncated portion of the string into the outgoing connection buffer without returning an error. This leads to silent data corruption, broken RPC routing, and unpredictable broker-side state behavior. --- ## Vulnerability Details ### Mechanism The vulnerability resides in the wire-level serialization logic for application publishing properties: ```go // write.go:246 length := uint8(len(b)) // wraps silently when len(b) > 255 (e.g., 300 -> 44) ``` Because Go allows silent integer truncation during explicit type casting, lengths larger than $2^8 - 1$ lose their most significant bits. The underlying stream writer reads `length` to determine how many bytes to pull from the buffer. Because no error or boundary check accompanies this truncation, the application believes the full payload was transmitted successfully. ### Affected Properties This truncation behavior affects every standard AMQP field serialized as a `shortstr`: * `CorrelationId` * `ReplyTo` * `MessageId` * `Expiration` * `UserId` * `AppId` * `ContentType` * `ContentEncoding` * `Type` ### Impact The critical consequence is **silent protocol desynchronization at the application layer**. The underlying TCP stream remains framed properly (because the shortened length matches the bytes written), but the business logic is corrupted. Distributed transactions, request-reply correlations, and tracing headers are truncated, causing downstream systems to drop messages or route them to incorrect consumers. --- ## Attack Vector An attacker who can influence metadata fields processed by an upstream application (such as a user-supplied tracking ID or a long content-type header) can exploit this to break system components: 1. **Targeting RPC Routing:** A user passes a malicious or overly long `CorrelationId` of 300 bytes through an application endpoint. 2. **Silent Truncation:** The library wraps the length value to 44, transmitting only the first 44 bytes to the rabbitMQ broker. 3. **Broken Correlation:** When the service processes the request and responds, the replying consumer attempts to route the message using the full 300-byte identifier. Because the broker only recognizes the truncated 44-byte ID, the reply loop breaks silently, leading to hanging processes or data leaks across transaction boundaries.
Recommended action
Recommended action
Upgrade affected packages to a patched version: github.com/rabbitmq/amqp091-go 1.13.0.
Technical details
- Vendor
- Not specified
- Product
- github.com/rabbitmq/amqp091-go
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source