CVE-2026-77403
— UNSCOREDpublic exploit availablePublished 2026-09-16 · Updated 2026-09-16
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.
Weaknesses
CWE-770
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-16100
- UNSCOREDCVE-2026-18401PoC
- MEDIUMCVE-2026-55996PoC
- MEDIUMCVE-2026-57173PoC
- HIGHCVE-2026-59675PoC
- UNSCOREDCVE-2026-61541PoC
- HIGHCVE-2026-61629PoC
- UNSCOREDCVE-2026-61652PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.