Описание
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
A flaw was found in amqp091-go, a Go AMQP 0.9.1 client. A malicious AMQP broker could exploit this by sending oversized data frames, forcing the client to allocate excessive memory. This can lead to unexpected memory consumption and potentially cause the application to become unavailable, resulting in a Denial of Service (DoS).
Отчет
This flaw in the amqp091-go client can lead to a denial of service in Red Hat products. A compromised or malicious AMQP broker could exploit this by sending oversized payloads, forcing the client to consume excessive memory and potentially causing application-layer service disruption. The impact is considered Important due to the potential for resource exhaustion and disruption of service.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Not affected | ||
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Not affected | ||
| OpenShift Serverless | openshift-serverless-1/kn-plugin-event-sender-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-operator-bundle | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Affected | ||
| Red Hat OpenStack Platform 18.0 | rhoso-operators/rabbitmq-cluster-rhel9-operator | Affected | ||
| Red Hat Quay 3 | quay/clair-rhel8 | Affected | ||
| Red Hat Quay 3 | quay/clair-rhel9 | Affected | ||
| Custom Metric Autoscaler 2.19 | custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9 | Fixed | RHSA-2026:62866 | 02.09.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...
amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload
EPSS
7.5 High
CVSS3