Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability involves the RabbitMQ Go AMQP client, where an oversized data field can cause parsing errors. This could disrupt connection integrity and availability if a malicious or compromised broker sends malformed data. The main concern is confirming relevance and exposure within your environment.
- Malformed broker data can disrupt client connections.
- Affects how applications communicate with message brokers.
- Confirm if your applications use this specific client.
Attack Path
How an attacker could exploit the issue
An attacker could disrupt a RabbitMQ connection by sending a specially crafted AMQP message with an oversized "longstr" field. This malformed data, when processed by the vulnerable client library, causes subsequent data to be misinterpreted. The library's incorrect handling of the oversized field leads to a desynchronization in parsing, allowing attacker-controlled data to be treated as legitimate message components, ultimately compromising the connection's integrity and availability.
- Requires network access to the client.
- Triggered by sending oversized AMQP data.
- Leads to connection integrity and availability disruption.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a malicious or compromised RabbitMQ broker could send an oversized AMQP longstr, causing the client library to misinterpret subsequent data. This can disrupt the connection and lead to a denial of service.
- Connection integrity and availability.
- Broker sends oversized longstr in table.
- Service disruption and denial of service.
Operational Fix
Recommended remediation, mitigation, and detection steps
The RabbitMQ amqp091-go client library is vulnerable to a parsing desynchronization when handling oversized AMQP longstr values. This could allow a malicious or compromised broker to disrupt connection integrity and availability by sending specially crafted data that causes subsequent parsing to read from the wrong offset. Given this is a client library, ownership typically falls to the application teams embedding it, with support from platform or infrastructure teams managing the message broker environment. The first practical step is to identify all applications using this library, assess their exposure to untrusted brokers, and plan remediation.
- Application teams own the fix.
- Verify broker trust and application usage.
- Plan updates during maintenance windows.