CVE-2026-107386 — amqp091-go is a Go AMQP 0.9.1 client.
Description
amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
None
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
Low
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
Affected
- Vendor
- Go
- Product
- github.com/rabbitmq/amqp091-go
Versions
- pkg:golang/github.com/rabbitmq/amqp091-go < 1.14.0
Stated as the source expressed them.
References
- advisory[email protected]https://github.com/rabbitmq/amqp091-go/commit/6723e8cff8710f0a6bf5fb4af375e285052535b3
- advisory[email protected]https://github.com/rabbitmq/amqp091-go/pull/377
- advisory[email protected]https://github.com/rabbitmq/amqp091-go/releases/tag/v1.14.0
- advisory[email protected]https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-w6r9-248c-frg8
- advisoryOSV GHSA-w6r9-248c-frg8https://osv.dev/vulnerability/GHSA-w6r9-248c-frg8
- vendorOSV packagehttps://github.com/rabbitmq/amqp091-go
Related threats
same CWE or vendorCVE-2026-78399 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow an authenticated user to cause a de…
CVE-2026-78399 · 2h ago
CVE-2026-107379 — savg-sanitizer is a PHP SVG/XML sanitizer.
CVE-2026-107379 · 5h ago
Coraza: Resource exhaustion via deferred file handle accumulation in multipart body processor
OSV · 5h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 5h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 5h ago
Coraza: Multipart filename* (RFC 5987) charset restriction lets a decoy filename bypass FILES-based rules
OSV · 5h ago