Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79921

Опубликовано: 26 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.

A flaw was found in amqp091-go, a Go AMQP 0.9.1 client. A malicious AMQP broker could exploit this by sending oversized data frames, forcing the client to allocate excessive memory. This can lead to unexpected memory consumption and potentially cause the application to become unavailable, resulting in a Denial of Service (DoS).

Отчет

This flaw in the amqp091-go client can lead to a denial of service in Red Hat products. A compromised or malicious AMQP broker could exploit this by sending oversized payloads, forcing the client to consume excessive memory and potentially causing application-layer service disruption. The impact is considered Important due to the potential for resource exhaustion and disruption of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Not affected
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Not affected
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Affected
Red Hat OpenStack Platform 18.0rhoso-operators/rabbitmq-cluster-rhel9-operatorAffected
Red Hat Quay 3quay/clair-rhel8Affected
Red Hat Quay 3quay/clair-rhel9Affected
Custom Metric Autoscaler 2.19custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9FixedRHSA-2026:6286602.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2524713github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via oversized AMQP payloads

EPSS

Процентиль: 24%
0.00316
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
22 дня назад

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.

nvd
22 дня назад

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.

debian
22 дня назад

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...

github
14 дней назад

amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload

EPSS

Процентиль: 24%
0.00316
Низкий

7.5 High

CVSS3