Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107386— amqp091-go: Pre-negotiation frame limit is not enforced to 4KB

Quick assessment

Affected
rabbitmq amqp091-go
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

amqp091-go 是一个 Go 语言实现的 AMQP 0.9.1 客户端库。从版本 1.13.0 到 1.14.0(不含),在连接调优(Connection.tune)完成之前,可以绕过此前内存分配建议中所描述的帧大小缓解措施。这是因为 Connection.maxFrameSize 在未协商状态和协商为无限制状态时均使用了零值。恶意或已被攻陷的 AMQP 对等端可以发送一个短小的 body-frame 头部,其中包含一个很大的声明负载长度,从而导致 ReadFrame 函数以及 body-frame 解析器在

CVSS 6.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
rabbitmq amqp091-go >= 1.13.0, < 1.14.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107386

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
amqp091-go: Pre-negotiation frame limit is not enforced to 4KB
Source: CVE Program / CVE List V5
Vulnerability Description
amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
rabbitmq amqp091-go >= 1.13.0, < 1.14.0 -

II. Public POCs for CVE-2026-107386

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107386

请登录查看更多情报信息。

Other References for CVE-2026-107386 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107386

No comments yet


Leave a comment