Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/rabbitmq/amqp091-go

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-77409 is a high-severity vulnerability in the RabbitMQ amqp091-go client prior to version 1.13.0. It involves allocation of resources without limits or throttling, where synchronous sending of publisher confirmations and other events to application channels can cause blocking if the listener channel is unbuffered, full, or not drained promptly. This can lead to connection stalls, missed heartbeats, deadlocks, and disconnections. The issue is fixed in version 1.13.0.

Join the discussion

CVE-2026-77411 affects the RabbitMQ amqp091-go client prior to version 1.13.0. The vulnerability arises from improper handling of oversized AMQP long string lengths in the readLongstr function, which returns an empty string and no error instead of an error. This causes the parser to become desynchronized, potentially allowing a malicious or compromised broker to disrupt connection integrity and availability by misinterpreting trailing bytes as valid fields or frames. The issue is fixed in version 1.13.0.

Join the discussion

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A malicious or compromised broker can encode a value such as 0xFFFFFFFF, which becomes -1 and causes a len out of range runtime panic. The panic escapes the network reader goroutine and terminates the client process, including during connection.start server properties or message header table parsing. This issue is fixed in version 1.13.0.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/rabbitmq/amqp091-go
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses