Disclosure summary
amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.
Source-reported weakness categories
CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107386
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-w6r9-248c-frg8
Open original source · Updated Oct 08, 2026
amqp091-go: Pre-negotiation frame limit is not enforced to 4KB
Source severity: MEDIUM / 6.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/rabbitmq/amqp091-go | < 1.14.0 | 1.14.0 |
Original records & references
PUBLISHED 2026-10-08T15:17:01-04:00
MODIFIED 2026-10-09T12:17:22-04:00
INGESTED 2026-10-10T20:55:03-04:00