{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/amqp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rabbitmq:amqp091-go:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-77411"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["amqp091-go (\u003c 1.13.0)"],"_cs_severities":["critical"],"_cs_tags":["data-integrity","serialization-vulnerability","protocol-corruption","denial-of-service","memory-exhaustion","amqp","vulnerability","credential-exposure","information-disclosure","injection"],"_cs_type":"advisory","_cs_vendors":["RabbitMQ"],"content_html":"\u003cp\u003eThe amqp091-go library (vulnerable versions prior to 1.13.0) contains a critical vulnerability (CVE-2026-77411) in the readLongstr function used to process AMQP wire-protocol data. When the parser encounters a string length field exceeding the maximum signed 32-bit integer (2^31 - 1), it triggers an improper error-handling condition. Instead of rejecting the malformed packet, the function performs a silent return, indicating a successful read of an empty string while failing to consume the associated bytes from the network buffer.\u003c/p\u003e\n\u003cp\u003eThis failure leaves the unprocessed payload in the TCP stream, causing the parser to become desynchronized from the actual frame boundaries. As subsequent read operations occur, the parser interprets attacker-controlled bytes as valid AMQP frame headers. This alignment shift allows an unauthenticated attacker to inject malicious AMQP frames - such as channel management or message publication commands - leading to potential connection hijacking or remote code execution within the application context.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability affects any Go-based application utilizing the rabbitmq/amqp091-go library for AMQP communication. Successful exploitation allows for complete bypass of the AMQP protocol state machine, enabling attackers to issue unauthorized commands or extract data processed by the library. This poses a significant risk to messaging infrastructure relying on the library for secure inter-service communication.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the amqp091-go package to version 1.13.0 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit network traffic logs for oversized string length parameters in AMQP payloads if deep packet inspection (DPI) or custom application-layer logging is available.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation at the application firewall level if upgrading is not immediately feasible, specifically targeting AMQP frame structures with anomalous length values.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T19:12:16Z","date_published":"2026-09-17T19:09:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rabbitmq-amqp091-desync/","summary":"A critical integer overflow vulnerability in the amqp091-go parser causes protocol desynchronization, allowing remote attackers to inject arbitrary AMQP frames into the network stream.","title":"Protocol Desynchronization and Frame Injection in RabbitMQ amqp091-go","url":"https://feed.craftedsignal.io/briefs/2026-09-rabbitmq-amqp091-desync/"}],"language":"en","title":"CraftedSignal Threat Feed - Amqp","version":"https://jsonfeed.org/version/1.1"}