CVE-2026-107386

NameCVE-2026-107386
Descriptionamqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
golang-github-rabbitmq-amqp091-go (PTS)bookworm1.5.0-2vulnerable
trixie1.10.0-1vulnerable
forky, sid1.15.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-rabbitmq-amqp091-gosource(unstable)1.14.0-1

Notes

https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-w6r9-248c-frg8
https://github.com/rabbitmq/amqp091-go/pull/377
Fixed by: https://github.com/rabbitmq/amqp091-go/commit/6723e8cff8710f0a6bf5fb4af375e285052535b3 (v1.14.0)
Relates to the mitigation applied for GHSA-r9c8-gcjp-xfwh / CVE-2026-77410

Search for package or bug name: Reporting problems