Bug 2548205 (CVE-2026-107386)

Summary: CVE-2026-107386 github.com/rabbitmq/amqp091-go: amqp091-go: Denial of Service via excessive memory allocation during frame parsing
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: aazores, cmah, dhanak, doconnor, drosa, dsimansk, eaguilar, ebaron, eglynn, gparvin, jbalunas, jjoyce, jmatsuok, jpretori, jschluet, jtolenti, kingland, lhh, mburns, mgarciac, mnovotny, pjindal, rhaigner, sausingh, tsze
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in amqp091-go. A malicious server or remote peer can cause a Denial of Service (DoS) by sending a crafted frame header declaring an excessively large payload size during initial connection setup. This flaw causes the client to allocate large amounts of memory before validating the frame or completing authentication, resulting in memory exhaustion and termination of the client process.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-10-08 19:12:07 UTC
amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.