CyberRota Analysis
AI-GeneratedThe RabbitMQ amqp091-go client is vulnerable due to improper handling of AMQP shortstr property values, allowing oversized inputs without error, which can lead to silent metadata corruption. This can disrupt request and reply correlation, routing, tracing, and downstream message processing, posing a critical risk to applications relying on these functionalities. Organizations utilizing versions prior to 1.13.0 should prioritize upgrading to mitigate this severe vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.