Skip to main content

CVE-2026-107386: CWE-770: Allocation of Resources Without Limits or Throttling in rabbitmq amqp091-go

0
Medium
Published: 10/08/2026 (10/08/2026, 19:40:19 UTC)
Source: CVE Database V5
Vendor/Project: rabbitmq
Product: amqp091-go

Description

## Summary The frame-size mitigation released in `amqp091-go` v1.13.0 can be bypassed before `connection.tune` completes. A malicious or compromised AMQP peer can send only a seven-byte body-frame header containing a large attacker-controlled `uint32` payload length. The client allocates a slice of that declared length before it verifies that the payload exists or rejects the frame for its invalid protocol state. The bypass occurs because `Connection.maxFrameSize` starts at zero. The reader interprets zero as both “negotiated unlimited” and “not negotiated yet,” and skips the pre-allocation size check in either case. `Open` starts the reader goroutine before negotiation and does not store a limit until after it receives `connection.tune`. This remains reachable even if the caller explicitly uses `Config{FrameSize: frameMinSize}`. A malicious broker can therefore cause excessive memory allocation, potentially terminating the Go client process through memory exhaustion, before authentication and connection setup complete. ## Relationship to the existing advisory [GHSA-r9c8-gcjp-xfwh](https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh) describes attacker-controlled, unbounded allocation by a malicious broker and identifies v1.13.0 as the patched version. [Pull request 369](https://github.com/rabbitmq/amqp091-go/pull/369) added a frame-size check before parser allocation, but the check is active only when the stored maximum is nonzero. The v1.13.0 source still: 1. starts the reader before protocol negotiation; 2. skips the bound while `maxFrameSize == 0`; 3. allocates the body using the peer-declared size; and 4. stores the negotiated maximum only after `connection.tune`. This appears to be an incomplete-fix or state-boundary bypass of the existing advisory rather than an unrelated allocation issue. ## Affected source and root cause The issue was reproduced at commit [`9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde`](https://github.com/rabbitmq/amqp091-go/commit/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde), dated 2026-07-30. The same relevant control flow is in the v1.13.0 tag. The vulnerable sequence is: 1. [`Open` starts `c.reader(conn)` before calling `c.open(config)`](https://github.com/rabbitmq/amqp091-go/blob/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde/connection.go#L373-L392). 2. [The reader receives a pointer to the initially zero-valued `c.maxFrameSize`](https://github.com/rabbitmq/amqp091-go/blob/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde/connection.go#L971-L979). 3. [`ReadFrame` decodes the peer-controlled `uint32` size but rejects it only when `max > 0`](https://github.com/rabbitmq/amqp091-go/blob/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde/read.go#L46-L79). 4. [`parseBodyFrame` executes `make([]byte, size)` before `io.ReadFull`](https://github.com/rabbitmq/amqp091-go/blob/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde/read.go#L459-L466). 5. [`maxFrameSize` is first stored after processing `connection.tune`](https://github.com/rabbitmq/amqp091-go/blob/9313fd9ea47bdb4e8f7f5db9bef94d5534d0bdde/connection.go#L1297-L1305). The source comments and regression tests explicitly combine “negotiated unlimited” with “not yet negotiated” as the same zero state. Those states need different security behavior. ## Safe reproduction This reproducer does not start RabbitMQ, contact any hosted service, send a large payload, or attempt to crash the process. It declares a 2 MiB body and observes the size of the slice passed to the transport's payload `Read`. Receiving a 2 MiB destination slice proves that the allocation occurred; the test then releases the blocked read and exits. 1. Check out v1.13.0. 2. Save the following as `pre_negotiation_frame_limit_test.go` in the repository root. 3. Run `go test -run '^TestPreNegotiationFrameLimitBypass$' -count=1 -v .`. ```go package amqp091 import ( "encoding/binary" "io" "sync" "testing" "time" ) const declaredBodySize = 2 << 20 type stagedFrameConn struct { mu sync.Mutex header []byte headerRead bool bodyRead chan int bodyOnce sync.Once release chan struct{} releaseOnce sync.Once } func newStagedFrameConn() *stagedFrameConn { header := make([]byte, 7) header[0] = frameBody binary.BigEndian.PutUint16(header[1:3], 1) binary.BigEndian.PutUint32(header[3:7], declaredBodySize) return &stagedFrameConn{ header: header, bodyRead: make(chan int, 1), release: make(chan struct{}), } } func (c *stagedFrameConn) Read(p []byte) (int, error) { c.mu.Lock() if !c.headerRead { c.headerRead = true n := copy(p, c.header) c.mu.Unlock() return n, nil } c.mu.Unlock() c.bodyOnce.Do(func() { c.bodyRead <- len(p) }) <-c.release return 0, io.EOF } func (c *stagedFrameConn) Write(p []byte) (int, error) { return len(p), nil } func (c *stagedFrameConn) Close() error { c.releaseOnce.Do(func() { close(c.release) }) return nil } func TestPreNegotiationFrameLimitBypass(t *testing.T) { conn := newStagedFrameConn

CVSS v4.0

Score 6.3medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected software

rabbitmq

amqp091-go

Affected versions
>=1.13.0 <1.14.0
github.com/rabbitmq/amqp091-go
pkg:golang/github.com/rabbitmq/amqp091-go
Affected versions
>=1.13.0 <1.14.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 20:49:08 UTC

Technical Analysis

The amqp091-go client versions >=1.13.0 and <1.14.0 have a resource allocation vulnerability (CWE-770) where the maxFrameSize field is zero before connection tuning completes. This allows an attacker to send a frame header declaring a large payload length, causing the client to allocate memory based on attacker-controlled size before verifying the frame's validity. This can lead to severe memory pressure, out-of-memory crashes, or client process termination prior to authentication. The vulnerability is reachable through the public Open method even when the FrameSize configuration is set to the protocol minimum. The issue is resolved in version 1.14.0.

Potential Impact

An attacker controlling or compromising an AMQP peer can exploit this vulnerability to cause the client to allocate excessive memory, potentially leading to denial of service via out-of-memory conditions or process termination before authentication completes. This impacts the stability and availability of the client application using affected versions of amqp091-go.

Mitigation Recommendations

Upgrade to amqp091-go version 1.14.0 or later, where this vulnerability is fixed. No other mitigations are indicated or required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.988Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ac7fef32cdf04f656318c0c

Added to database: 10/08/2026, 20:37:07 UTC

Last enriched: 10/08/2026, 20:49:08 UTC

Last updated: 10/08/2026, 21:45:51 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses