{"id":"CVE-2026-79921","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-79921","summary":"amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that…","details":"amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.","published":"2026-08-26T21:16:41.873","modified":"2026-08-26T21:16:41.873","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0","label":"rabbitmq/amqp091-go@6beb7b5"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/pull/353"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-26T21:16:41.873"}}