Skip to content
archivevulnerability · 17 Sep 2026 · 17:04 UTC

GHSA-c5pq-fr2g-9jpf: RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr

VULNCVE-2026-77411source · GTH
HIGHCritical vulnerability
What to do
  • Critical severity — schedule an urgent patch.

last 60 dispatches · spectrum

**Summary** A critical stream desynchronization vulnerability has been identified in the AMQP wire-protocol parser. When parsing a long string (`readLongstr`) within a table field, providing a length that exceeds the maximum signed 32-bit integer (`2^31 - 1`, or roughly `2.1` GiB) triggers an improper error-handling condition. The parser abruptly aborts the read and returns a success status (`"",nil`) without consuming the specified bytes from the underlying network buffer. This causes all subsequent read operations to become misaligned. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected