CVE-2026-79921
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
26/08/2026
Last modified:
26/08/2026
Description
amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.
Impact
Base Score 4.0
8.90
Severity 4.0
HIGH



