OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-77411

CRITICAL · CVSS 9.5 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The RabbitMQ amqp091-go client prior to version 1.13.0 is vulnerable to a critical issue where the readLongstr function mishandles oversized AMQP longstr lengths, leading to potential desynchronization in message parsing. This flaw allows a malicious broker to inject attacker-controlled data, compromising connection integrity and availability. Organizations using this client should prioritize upgrading to version 1.13.0 to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77411
Severity
CRITICAL
CVSS
9.5
EPSS
0.52%

Original NVD Description

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the declared field bytes unread, while readTable treats the operation as successful and continues parsing from the wrong offset. A malicious or compromised broker can provide an oversized longstr in a table field and desynchronize subsequent AMQP parsing, causing attacker-controlled trailing bytes to be interpreted as later fields or frames and disrupting connection integrity and availability. This issue is fixed in version 1.13.0.