{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/amqp091-go--1.13.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rabbitmq:amqp091-go:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-79921"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["amqp091-go (\u003c 1.13.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["RabbitMQ"],"content_html":"\u003cp\u003eThe amqp091-go library (versions prior to 1.13.0) contains a vulnerability (CVE-2026-79921) related to improper input validation during the processing of AMQP 0-9-1 frames. During the initial connection handshake, both the client and broker negotiate a maximum frame size (frame_max) to govern data transfer parameters.\u003c/p\u003e\n\u003cp\u003eResearchers identified that the library fails to enforce this established constraint when receiving content body frames. If a malicious or compromised broker transmits a frame header declaring a payload size that exceeds the agreed-upon frame_max, the library trustfully accepts the value. This results in the client performing memory allocations dictated by the broker rather than the negotiated protocol limits. An attacker acting as a rogue broker can exploit this behavior by sending frames with excessively large declared sizes, leading to significant memory exhaustion and potential Out-Of-Memory (OOM) application crashes. This vulnerability represents a failure of the client to adhere to the security constraints defined by the AMQP 0-9-1 specification.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to an application-layer Denial of Service (DoS) against any service or client utilizing the amqp091-go library to connect to an untrusted or compromised AMQP broker. This can result in service instability, application crashes, and potential disruption of dependent message-processing workflows.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the amqp091-go library to version 1.13.0 or later immediately to incorporate proper frame size validation.\u003c/li\u003e\n\u003cli\u003eReview connection configurations to ensure that clients are only interacting with trusted or hardened AMQP broker infrastructure.\u003c/li\u003e\n\u003cli\u003eMonitor application memory metrics and infrastructure logs for anomalous growth or OOM events associated with the Go service binary.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T00:06:54Z","date_published":"2026-09-04T00:06:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-amqp-mem-exhaustion/","summary":"The amqp091-go library fails to enforce negotiated frame size limits, allowing a malicious AMQP broker to trigger arbitrary memory allocation and application-layer denial of service via CVE-2026-79921.","title":"Memory Exhaustion in amqp091-go Client via Oversized AMQP Frames","url":"https://feed.craftedsignal.io/briefs/2026-09-amqp-mem-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Amqp091-Go (\u003c 1.13.0)","version":"https://jsonfeed.org/version/1.1"}