github.com/rabbitmq/amqp091-go
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/rabbitmq/amqp091-gopage 1 of 1
- CVE-2026-77405CRITICALCVSS 9.4EG 9.4✓ Fixed in 1.13.02026-09-16
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can the…
- CVE-2026-77412HIGHCVSS 8.9EG 8.9✓ Fixed in 1.13.02026-09-16
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer. A…
- CVE-2026-79921HIGHCVSS 8.9EG 8.9✓ Fixed in 1.13.02026-08-26
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to…
Check whether github.com/rabbitmq/amqp091-go is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/rabbitmq/amqp091-go CVEs against the assets you own.
Start Free Scan →