blob: ecbeeee5295485ea20aa78ffdf8639b75754d3a3 [file]
id: GO-2026-6500
modules:
- module: github.com/rabbitmq/amqp091-go
versions:
- fixed: 1.13.0
vulnerable_at: 1.12.0
packages:
- package: github.com/rabbitmq/amqp091-go
symbols:
- Channel.recvContent
derived_symbols:
- Connection.Reconnect
- DefaultConnectionRecovery.OnConnectionClose
- Dial
- DialConfig
- DialTLS
- DialTLS_ExternalAuth
- Open
summary: |-
RabbitMQ amqp091-go: Resource Exhaustion (OOM) via Unbounded Body Buffer
Allocation in github.com/rabbitmq/amqp091-go
cves:
- CVE-2026-77410
ghsas:
- GHSA-r9c8-gcjp-xfwh
references:
- advisory: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-77410
- fix: https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382
- fix: https://github.com/rabbitmq/amqp091-go/pull/346
- web: https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
source:
id: GHSA-r9c8-gcjp-xfwh
created: 2026-09-28T14:14:34.511097-04:00
review_status: NEEDS_REVIEW