CVE-2026-107386
Last modified
CVE-2026-107386 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states.
Description
amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| rabbitmq | amqp091-go | >= 1.13.0, < 1.14.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-107386?
How severe is CVE-2026-107386?
How do I fix CVE-2026-107386?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-10738The jQuery Hover Footnotes plugin for WordPress is vulnerabl…6.4
- CVE-2026-107380savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, s…5.4
- CVE-2026-107382MariaDB Connector/Node.js is used to connect applications de…5.9
- CVE-2026-107383MariaDB Connector/Node.js is used to connect applications de…7.5
- CVE-2026-107384MariaDB Connector/Node.js is used to connect applications de…8.1
- CVE-2026-107385MariaDB Connector/Node.js is used to connect applications de…7.4
- CVE-2026-107387music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-107388music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-107389music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-10739Cato Networks SDP Client for Windows before 6.12.6 allows a …8.5
- CVE-2026-107390music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-107391music-metadata is a metadata parser for audio and video medi…6.2
Are you affected by CVE-2026-107386?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
