| id: GO-2026-6500 |
| modules: |
| - module: github.com/rabbitmq/amqp091-go |
| versions: |
| - fixed: 1.13.0 |
| vulnerable_at: 1.12.0 |
| packages: |
| - package: github.com/rabbitmq/amqp091-go |
| symbols: |
| - Channel.recvContent |
| derived_symbols: |
| - Connection.Reconnect |
| - DefaultConnectionRecovery.OnConnectionClose |
| - Dial |
| - DialConfig |
| - DialTLS |
| - DialTLS_ExternalAuth |
| - Open |
| summary: |- |
| RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer |
| Allocation in github.com/rabbitmq/amqp091-go |
| cves: |
| - CVE-2026-77410 |
| ghsas: |
| - GHSA-r9c8-gcjp-xfwh |
| references: |
| - advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77410 |
| - fix: https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382 |
| - fix: https://github.com/rabbitmq/amqp091-go/pull/346 |
| - web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0 |
| source: |
| id: GHSA-r9c8-gcjp-xfwh |
| created: 2026-09-28T14:14:34.511097-04:00 |
| review_status: NEEDS_REVIEW |