<Vulnerability name="CVE-2026-77403">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-09-16T14:36:19</PublicDate>
    <Bugzilla id="2535498" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535498" xml:lang="en:us">
github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-839</CWE>
    <Details xml:lang="en:us" source="Mitre">
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not enforce the protocol minimum. A malicious or compromised AMQP broker can therefore advertise an extremely small FrameMax, causing later client publications to be fragmented into excessive numbers of frames and write operations. This can consume CPU and stall the client or its host. This issue is fixed in version 1.13.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in RabbitMQ amqp091-go, a Go AMQP 0.9.1 client. A malicious or compromised AMQP broker can exploit this by advertising an extremely small frame size during connection negotiation. This can lead to excessive fragmentation of client publications, consuming significant CPU resources and potentially causing a Denial of Service (DoS) by stalling the client or its host.
    </Details>
    <Mitigation xml:lang="en:us">
To mitigate this issue, ensure that applications using the RabbitMQ amqp091-go client only connect to trusted AMQP brokers. Restrict network access for clients to only communicate with known, secure broker instances. This reduces the risk of a malicious or compromised broker exploiting the client's vulnerability during frame size negotiation.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-09-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:68290">RHSA-2026:68290</Advisory>
        <Package name="opentelemetry-collector-contrib-main">opentelemetry-collector-contrib-main-0.161.0-0.1.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:cryostat:4">
        <ProductName>Cryostat 4</ProductName>
        <FixState>Affected</FixState>
        <PackageName>cryostat/cryostat-storage-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-serverless-1/kn-plugin-event-sender-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/acm-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-operator-bundle</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhoso-operators/rabbitmq-cluster-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-77403
https://nvd.nist.gov/vuln/detail/CVE-2026-77403
https://github.com/rabbitmq/amqp091-go/commit/2e0a919b89f337dbf58db2bb34ab206dac354a06
https://github.com/rabbitmq/amqp091-go/pull/353
https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-xwwf-m8fg-p9q2
    </References>
</Vulnerability>