OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-77408

CRITICAL · CVSS 9.1 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The RabbitMQ amqp091-go client is vulnerable due to improper handling of AMQP shortstr property values, allowing oversized inputs without error, which can lead to silent metadata corruption. This can disrupt request and reply correlation, routing, tracing, and downstream message processing, posing a critical risk to applications relying on these functionalities. Organizations utilizing versions prior to 1.13.0 should prioritize upgrading to mitigate this severe vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77408
Severity
CRITICAL
CVSS
9.1
EPSS
0.52%

Original NVD Description

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.