Back to database
Soon63Medium6.3VulnerabilityCVE-2026-107386No patch link observed

CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.

Published Oct 8, 2026, 07:17 PM UTCIngested 4h agoSource NVD(cve-db)CVE-2026-107386

Description

amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
6.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

Present

Attack Requirements

PR

None

Privileges Required

UI

None

User Interaction

VC

None

Confidentiality (Vulnerable System)

VI

None

Integrity (Vulnerable System)

VA

Low

Availability (Vulnerable System)

SC

None

Confidentiality (Subsequent System)

SI

None

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)

Affected

Vendor
Go
Product
github.com/rabbitmq/amqp091-go

Versions

  • pkg:golang/github.com/rabbitmq/amqp091-go < 1.14.0

Stated as the source expressed them.