<Vulnerability name="CVE-2026-77404">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T14:40:49</PublicDate>
    <Bugzilla id="2535489" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535489" xml:lang="en:us">
github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>8.8</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-140</CWE>
    <Details xml:lang="en:us" source="Mitre">
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters with url.Values. If an application accepts a TLS asset path containing ampersand or equals delimiters and later reparses the serialized URI with ParseURI, the embedded delimiters can create or overwrite connection options, including paths to TLS certificate, key, or CA files. This can corrupt connection configuration or select unintended local cryptographic assets. This issue is fixed in version 1.13.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in RabbitMQ amqp091-go. The URI.String function in uri.go concatenates TLS asset path values directly into an AMQPS query string without proper encoding. If an application processes a TLS asset path containing special characters like ampersand or equals delimiters, these can be misinterpreted during URI re-parsing. This vulnerability could allow an attacker to overwrite connection options, potentially corrupting the connection configuration or selecting unintended local cryptographic assets, leading to a compromise of the TLS connection.
    </Details>
    <Statement xml:lang="en:us">
This flaw has an Important impact because applications in Red Hat products that use amqp091-go and accept attacker-controlled TLS asset paths can be induced to reparse a crafted AMQPS URI. A local attacker with partial control of a certificate, key, CA, or server-name path or related environment setting can inject query parameters and alter connection configuration, potentially selecting unintended local TLS material or causing connection failures.
    </Statement>
    <Mitigation xml:lang="en:us">
Avoid accepting untrusted values for TLS certificate, key, CA, or server-name paths. Restrict write access to directories and environment settings used to configure those paths, and upgrade applications using amqp091-go to version 1.13.0 or later when available.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-09-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:68290">RHSA-2026:68290</Advisory>
        <Package name="opentelemetry-collector-contrib-main">opentelemetry-collector-contrib-main-0.161.0-0.1.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:cryostat:4">
        <ProductName>Cryostat 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>cryostat/cryostat-storage-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-serverless-1/kn-plugin-event-sender-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/acm-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-operator-bundle</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhoso-operators/rabbitmq-cluster-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-77404
https://nvd.nist.gov/vuln/detail/CVE-2026-77404
https://github.com/rabbitmq/amqp091-go/commit/743d488e46955fe7ffc55506fe2c401d01216783
https://github.com/rabbitmq/amqp091-go/pull/352
https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-465g-fh3v-9jw4
    </References>
</Vulnerability>