AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-107386.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 6.3CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSDeferredModified Oct 09, 2026

Disclosure summary

amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.

Source-reported weakness categories

CWE-770

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-107386

Open original source · Updated Oct 09, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-w6r9-248c-frg8

Open original source · Updated Oct 08, 2026

amqp091-go: Pre-negotiation frame limit is not enforced to 4KB

Source severity: MEDIUM / 6.3

EcosystemPackageAffected rangeFirst patched
gogithub.com/rabbitmq/amqp091-go< 1.14.01.14.0

Original records & references

PUBLISHED 2026-10-08T15:17:01-04:00
MODIFIED 2026-10-09T12:17:22-04:00
INGESTED 2026-10-10T20:55:03-04:00