Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-77403

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.

A flaw was found in RabbitMQ amqp091-go, a Go AMQP 0.9.1 client. A malicious or compromised AMQP broker can exploit this by advertising an extremely small frame size during connection negotiation. This can lead to excessive fragmentation of client publications, consuming significant CPU resources and potentially causing a Denial of Service (DoS) by stalling the client or its host.

Меры по смягчению последствий

To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Affected
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operatorAffected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleAffected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-839
https://bugzilla.redhat.com/show_bug.cgi?id=2535498github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation

EPSS

Процентиль: 35%
0.00411
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
3 дня назад

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.

debian
3 дня назад

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connec ...

github
2 дня назад

RabbitMQ amqp091-go: Denial of Service via Sub-Spec Frame Size Negotiation

EPSS

Процентиль: 35%
0.00411
Низкий

7.5 High

CVSS3