CVE-2026-79921

EUVD-2026-66715
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 23.91%
Debian logo
Debian Releases
Debian Product
Codename
golang-github-rabbitmq-amqp091-go
bookworm
vulnerable
forky
vulnerable
sid
1.14.0-1
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-rabbitmq-amqp091-go
jammy
dne
noble
needs-triage
resolute
needs-triage