---
id: CVE-2026-107386
title: amqp091-go is a Go AMQP 0.9.1 client
summary: >-
  amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size
  mitigation from the prior allocation advisory can be bypassed before
  connection.tune completes because Connection.maxFrameSize uses zero for both
  the not-yet-…
severity: medium
cwe:
  - CWE-770
vendor: rabbitmq
product: github.com/rabbitmq/amqp091-go
affected:
  - github.com/rabbitmq/amqp091-go < 1.14.0
patched:
  - github.com/rabbitmq/amqp091-go 1.14.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107386'
references:
  - url: >-
      https://github.com/rabbitmq/amqp091-go/commit/6723e8cff8710f0a6bf5fb4af375e285052535b3
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/amqp091-go/pull/377'
    label: security-advisories@github.com
  - url: 'https://github.com/rabbitmq/amqp091-go/releases/tag/v1.14.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-w6r9-248c-frg8
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-w6r9-248c-frg8'
  - url: 'https://github.com/rabbitmq/amqp091-go'
tags:
  - nvd
  - ghsa
  - go
  - osv
aliases:
  - GHSA-w6r9-248c-frg8
ecosystem: go
ingestedAt: '2026-10-08T20:06:22.186Z'
---

## Overview

amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14.0, the frame-size mitigation from the prior allocation advisory can be bypassed before connection.tune completes because Connection.maxFrameSize uses zero for both the not-yet-negotiated and negotiated-unlimited states. A malicious or compromised AMQP peer can send a short body-frame header with a large declared payload length, causing ReadFrame and the body-frame parser to allocate attacker-selected memory before the payload is received or the frame's protocol state is rejected. The condition is reachable through public Open even when Config.FrameSize is set to the protocol minimum and can cause severe memory pressure, out-of-memory termination, or loss of the client process before authentication completes. This issue is fixed in version 1.14.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107386)

Affected packages:

- `github.com/rabbitmq/amqp091-go < 1.14.0`

Patched in:

- `github.com/rabbitmq/amqp091-go 1.14.0`

Source: https://github.com/advisories/GHSA-w6r9-248c-frg8
