CVE-2026-77408: CWE-190: Integer Overflow or Wraparound in rabbitmq amqp091-go
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
AI Analysis
Technical Summary
RabbitMQ amqp091-go versions prior to 1.13.0 contain an integer overflow or wraparound vulnerability (CWE-190) in the writeShortstr function within write.go. This function casts the byte length of AMQP short string property values to a uint8 type without rejecting values longer than 255 bytes. As a result, if an application accepts oversized values for properties like CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type, the serialized length wraps around, causing only a truncated prefix to be serialized without error. This silent metadata corruption can break request-reply correlation, routing, tracing, and downstream message processing. The issue is resolved in version 1.13.0.
Potential Impact
The vulnerability can cause silent corruption of AMQP message metadata, leading to failures in request and reply correlation, message routing, tracing, and downstream processing. This can disrupt the normal operation of applications relying on these message properties for correct functionality. There is no indication of remote code execution or privilege escalation, but the impact on message integrity and processing is significant.
Mitigation Recommendations
Upgrade to RabbitMQ amqp091-go version 1.13.0 or later, where this issue is fixed. No other mitigation is indicated or required.
CVE-2026-77408: CWE-190: Integer Overflow or Wraparound in rabbitmq amqp091-go
Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.
CVSS v4.0
Score 9.1critical
Affected software
rabbitmq
amqp091-go
pkg:golang/github.com/rabbitmq/amqp091-goRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
RabbitMQ amqp091-go versions prior to 1.13.0 contain an integer overflow or wraparound vulnerability (CWE-190) in the writeShortstr function within write.go. This function casts the byte length of AMQP short string property values to a uint8 type without rejecting values longer than 255 bytes. As a result, if an application accepts oversized values for properties like CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type, the serialized length wraps around, causing only a truncated prefix to be serialized without error. This silent metadata corruption can break request-reply correlation, routing, tracing, and downstream message processing. The issue is resolved in version 1.13.0.
Potential Impact
The vulnerability can cause silent corruption of AMQP message metadata, leading to failures in request and reply correlation, message routing, tracing, and downstream processing. This can disrupt the normal operation of applications relying on these message properties for correct functionality. There is no indication of remote code execution or privilege escalation, but the impact on message integrity and processing is significant.
Mitigation Recommendations
Upgrade to RabbitMQ amqp091-go version 1.13.0 or later, where this issue is fixed. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-20T19:55:27.023Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aaaac0055bf5e2cf5bf8d58
Added to database: 09/16/2026, 14:47:28 UTC
Last enriched: 09/16/2026, 15:01:28 UTC
Last updated: 09/17/2026, 02:00:20 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.