{"id":"GHSA-rm6m-hrcw-jw33","summary":"RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration","details":"## Summary\nA logic and resource exhaustion vulnerability exists in the AMQP client's Quality of Service (`Qos`) configuration method. The `Qos` function accepts signed integers (`int`) for the `prefetchCount` and `prefetchSize` parameters but casts them directly to unsigned integers (`uint16` and `uint32`, respectively) when formatting the wire-level frame.\n\nIf a developer passes a negative integer (such as `-1`) to these parameters—frequently intended as a sentinel value meaning \"no change\" or \"no limit\"—the application performs an implicit signed-to-unsigned conversion. This wraps the values to their absolute maximum limit ($65535$ and $4294967295$). Consequently, a consumer expecting restricted message delivery rates is suddenly flooded with an unlimited volume of messages, potentially exhausting memory resources and crashing the application.\n\n---\n\n## Vulnerability Details\n\n### Mechanism\nThe bug manifests during the structural assignment inside the channel's `Qos` method:\n\n```go\n// channel.go:795-796\nPrefetchCount: uint16(prefetchCount),  // -1 wraps to 65535\nPrefetchSize:  uint32(prefetchSize),   // -1 wraps to 4294967295\n```\n\nIn Go, converting a negative signed integer to an unsigned integer shifts the value via two's complement arithmetic. Because no boundary validation or signedness check occurs prior to the cast:\n* Passing `-1` for `prefetchCount` yields a wire value of `65535`.\n* Passing `-1` for `prefetchSize` yields a wire value of `4294967295`.\n\n### Impact\nThe AMQP broker interprets a `prefetch-count` of `65535` as an instruction to dispatch messages to the consumer with virtually no concurrency limits. \n\nIf the application is processing heavy payloads or relies on strict rate-limiting to maintain stability, this unexpected flood will cause rapid heap memory growth, unmanageable processing queues, and an eventual Out-Of-Memory (OOM) termination.\n\n---\n\n## Attack Vector\nAn attacker who can manipulate configuration files, environmental variables, or API inputs that dictate client Qos settings can trigger an application-layer Denial of Service:\n\n1. **Malicious Input:** An attacker sets a service's prefetch configuration parameter to `-1`.\n2. **Implicit Overflow:** The application initializes the channel, executes `Qos(-1, ...)`, and transmits an unintended maximum-capacity request to the RabbitMQ/AMQP broker.\n3. **Consumer Exhaustion:** The broker flushes the entire contents of the queue directly into the client consumer's network buffer, bypassing expected application concurrency barriers and inducing a crash.","aliases":["CVE-2026-77406"],"modified":"2026-09-17T17:15:04.039467861Z","published":"2026-09-17T17:04:05Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-17T17:04:05Z","nvd_published_at":"2026-09-16T15:17:49Z","cwe_ids":["CWE-195"]},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-rm6m-hrcw-jw33"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77406"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/pull/351"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/commit/3b879e1d1d25b544e26b3bc3d7db3213203c0f3b"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/amqp091-go"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0"}],"affected":[{"package":{"name":"github.com/rabbitmq/amqp091-go","ecosystem":"Go","purl":"pkg:golang/github.com/rabbitmq/amqp091-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rm6m-hrcw-jw33/GHSA-rm6m-hrcw-jw33.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L"}]}