{"id":"GHSA-r9c8-gcjp-xfwh","summary":"RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer Allocation","details":"**Summary**\nA flaw in the `recvContent` function allows a malicious AMQP server to trigger an Out-of-Memory (OOM) error, forcing the host operating system or container runtime to immediately terminate the client process.\n\n**Vulnerability Details**\nWhen receiving message content payloads, the client processes the expected size from the content header framework. The `recvContent` function attempts to optimize performance by pre-allocating memory for the message body based on the `ch.header.Size` field, which is a 64-bit unsigned integer (`uint64`).\n\n```go\n// channel.go:495-496\nif cap(ch.body) == 0 {\n    ch.body = make([]byte, 0, ch.header.Size)  // unbounded\n}\n```\n\nThe underlying library fails to validate or cap this requested size against any upper boundary—such as the maximum frame size negotiated during connection establishment (`FrameMax`). If a server specifies an extreme body size (e.g., `2^62` bytes), the Go runtime attempts to allocate an exabyte-scale slice capacity. This immediately exhausts available system memory, causing the operating system's OOM killer to terminate the application.\n\n**Attack Vector / Exploitation Scenario**\n\n- Message Delivery Phase: A malicious or compromised AMQP broker sends a standard `basic.deliver` frame containing a content header with an intentionally inflated `body-size` variable.\n- Authentication Requirement: No special privileges or authentication bypasses are required; the crash occurs seamlessly during normal message consumption.\n\n**Impact**\n\n- Availability: High. Exploded memory consumption results in an instant process termination, destroying application state and availability for all threads sharing the environment.","aliases":["CVE-2026-77410"],"modified":"2026-09-17T17:15:04.675319552Z","published":"2026-09-17T17:04:20Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-17T17:04:20Z","nvd_published_at":"2026-09-16T15:17:50Z","cwe_ids":["CWE-789"]},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77410"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/pull/346"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/amqp091-go"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0"}],"affected":[{"package":{"name":"github.com/rabbitmq/amqp091-go","ecosystem":"Go","purl":"pkg:golang/github.com/rabbitmq/amqp091-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-r9c8-gcjp-xfwh/GHSA-r9c8-gcjp-xfwh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H"}]}