
Upwind Security MDR@UpwindMDR
🚨High - amqp091-go oversized longstr mishandling (CVE-2026-77411) In rabbitmq/amqp091-go before 1.13.0, readLongstr returns "" + nil (instead of ErrSyntax) when an AMQP longstr length exceeds 0x7FFFFFFF. A malicious or compromised broker can craft a table field that leaves bytes unread, so readTable continues from the wrong offset and misinterprets attacker-controlled trailing data as later fields/frames. This breaks connection integrity and enables DoS. 👉Affected: http://github.com/rabbitmq/amqp091-go < 1.13.0 | Upgrade to 1.13.0
0000062
303 followersView on X
