{"id":"GHSA-4v58-74mf-rjx3","summary":"RabbitMQ amqp091-go: Denial of Service via Malicious Field Length in AMQP Client","details":"**Summary**\nA vulnerability in the readField function allows a malicious or compromised AMQP server to trigger an unhandled runtime panic in the client application, leading to an immediate crash of the entire process.\n\n**Details**\nWhen parsing incoming AMQP frames, the `readField` function processes byte-array fields (type tag `'x'`) by reading a 32-bit big-endian integer to determine the length of the data payload.\n\n```go\n// read.go:253-263\ncase 'x':\n    var len int32\n    if err = binary.Read(r, binary.BigEndian, &len); err != nil {\n        return nil, err\n    }\n    value := make([]byte, len)  // PANICS if len \u003c 0\n```\n\nIf a server transmits a length value of `0xFFFFFFFF`, it is interpreted by the client as a signed 32-bit integer with a value of `-1`. Passing a negative integer to Go's built-in make() function for slice allocation triggers an unrecoverable runtime panic (panic: len out of range).\n\nBecause the reader goroutine handles network I/O without an explicit recover() wrapper, this panic propagates up to the runtime root, abruptly terminating the host application.\n\n**Attack Vector / Exploitation Scenario**\nAn attacker capable of spoofing, compromising, or controlling an AMQP broker can exploit this flaw during two primary phases:\n\n1. Connection Establishment: Sending a malicious connection.start handshake frame containing server-properties with an 'x' type field assigned a negative length.\n2. Message Delivery: Delivering a message payload where the header table contains a malformed field matching the criteria above.\n\n**Impact**\nAvailability: High. A single malformed frame can reliably crash the client process, resulting in a persistent Denial of Service (DoS) if the client automatically reconnects and receives the same payload.","aliases":["CVE-2026-77412","GO-2026-6494"],"modified":"2026-10-01T20:55:57.301161595Z","published":"2026-09-17T17:04:29Z","database_specific":{"github_reviewed_at":"2026-09-17T17:04:29Z","nvd_published_at":"2026-09-16T15:17:50Z","cwe_ids":["CWE-681"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-4v58-74mf-rjx3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77412"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/pull/344"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/commit/669b42bf7b1db76bc6d4973e3634247f680accbf"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/amqp091-go"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0"}],"affected":[{"package":{"name":"github.com/rabbitmq/amqp091-go","ecosystem":"Go","purl":"pkg:golang/github.com/rabbitmq/amqp091-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-4v58-74mf-rjx3/GHSA-4v58-74mf-rjx3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}]}