External risk intelligence

RabbitMQ Go Client Oversized Longstr Parsing Desynchronization

CVE advisorySeverity: CRITICAL (CVSS 9.5)

CVE-2026-77411

This is a client-side library used by applications to communicate with a message broker. While network-reachable, the library itself is typically embedded within internal application code rather than acting as a public-facing service, gateway, or edge endpoint.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves the RabbitMQ Go AMQP client, where an oversized data field can cause parsing errors. This could disrupt connection integrity and availability if a malicious or compromised broker sends malformed data. The main concern is confirming relevance and exposure within your environment.

  • Malformed broker data can disrupt client connections.
  • Affects how applications communicate with message brokers.
  • Confirm if your applications use this specific client.

Attack Path

How an attacker could exploit the issue

An attacker could disrupt a RabbitMQ connection by sending a specially crafted AMQP message with an oversized "longstr" field. This malformed data, when processed by the vulnerable client library, causes subsequent data to be misinterpreted. The library's incorrect handling of the oversized field leads to a desynchronization in parsing, allowing attacker-controlled data to be treated as legitimate message components, ultimately compromising the connection's integrity and availability.

  • Requires network access to the client.
  • Triggered by sending oversized AMQP data.
  • Leads to connection integrity and availability disruption.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a malicious or compromised RabbitMQ broker could send an oversized AMQP longstr, causing the client library to misinterpret subsequent data. This can disrupt the connection and lead to a denial of service.

  • Connection integrity and availability.
  • Broker sends oversized longstr in table.
  • Service disruption and denial of service.

Operational Fix

Recommended remediation, mitigation, and detection steps

The RabbitMQ amqp091-go client library is vulnerable to a parsing desynchronization when handling oversized AMQP longstr values. This could allow a malicious or compromised broker to disrupt connection integrity and availability by sending specially crafted data that causes subsequent parsing to read from the wrong offset. Given this is a client library, ownership typically falls to the application teams embedding it, with support from platform or infrastructure teams managing the message broker environment. The first practical step is to identify all applications using this library, assess their exposure to untrusted brokers, and plan remediation.

  • Application teams own the fix.
  • Verify broker trust and application usage.
  • Plan updates during maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the RabbitMQ amqp091-go library?

This software is a Go-language client library that allows applications to communicate with RabbitMQ or other message brokers using the AMQP 0.9.1 protocol. Developers embed this library into their Go services to send and receive messages across distributed systems. It acts as the bridge that manages the network connection and data serialization between your application code and the messaging infrastructure.

How does CVE-2026-77411 cause a parsing issue?

The vulnerability involves improper handling of unexpected input, classified as CWE-754. In older versions of the library, specifically when processing an oversized string field, the code incorrectly signals success instead of failing. This causes the parser to skip over data and continue reading from the wrong offset, leading to a state where the library misinterprets subsequent message frames as valid data.

When does this vulnerability trigger?

The flaw is triggered only when the client library receives a specific, malformed AMQP message from a broker that contains an oversized string field. Normal, well-formed messages will not trigger the bug. Furthermore, the issue specifically requires the client to process a maliciously crafted table field; standard operation with a trusted, properly configured broker will not initiate this desynchronization.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal indicates that risk is unlikely for most environments. Because this is a client library embedded within your internal application code, it generally does not act as a public-facing service or internet gateway. However, if your application connects to a broker that might be compromised or potentially interacts with untrusted external message sources, the risk profile changes.

What is the first step to remediate this CVE?

The primary action is to identify all internal services that import the amqp091-go library and update them to version 1.13.0 or later. Since this is an embedded dependency, application teams are responsible for updating the code and redeploying their services. Once updated, verify that your applications maintain stable connections to your message brokers.

References