<Vulnerability name="CVE-2026-77409">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T14:48:00</PublicDate>
    <Bugzilla id="2535494" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535494" xml:lang="en:us">
github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, consumer cancellations, returned messages, including NotifyConfirm events and connection block notifications, to application-provided channels. If a listener channel is unbuffered, full, or not drained promptly, the sole reader goroutine blocks and stops processing frames, acknowledgments, deliveries, and heartbeats. Broker-driven event bursts can therefore cause connection stalls, missed heartbeats, deadlocks, and disconnection. This issue is fixed in version 1.13.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in RabbitMQ amqp091-go, a Go AMQP 0.9.1 client. When the client synchronously sends events to application-provided channels, an unbuffered or full listener channel can cause the client's reader to block. This blockage prevents the processing of critical messages and heartbeats, leading to connection stalls, deadlocks, and disconnections. This vulnerability can result in a Denial of Service (DoS) for applications using the affected component.
    </Details>
    <Statement xml:lang="en:us">
This flaw has an Important impact because a broker-driven event burst can block AMQP client processing when application notification channels are unbuffered, full, or not promptly drained. The resulting stall can cause missed heartbeats, deadlocks, or client disconnection.
    </Statement>
    <Mitigation xml:lang="en:us">
Use adequately buffered notification channels and ensure event consumers continuously drain them. Update applications using amqp091-go when a fixed version is available.
    </Mitigation>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-09-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:68290">RHSA-2026:68290</Advisory>
        <Package name="opentelemetry-collector-contrib-main">opentelemetry-collector-contrib-main-0.161.0-0.1.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:cryostat:4">
        <ProductName>Cryostat 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>cryostat/cryostat-storage-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-serverless-1/kn-plugin-event-sender-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/acm-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-operator-bundle</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhoso-operators/rabbitmq-cluster-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-77409
https://nvd.nist.gov/vuln/detail/CVE-2026-77409
https://github.com/rabbitmq/amqp091-go/commit/5b0ccbb8d7bc3dfa18129d9b0f9256d656809494
https://github.com/rabbitmq/amqp091-go/pull/349
https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-wxx3-cj7g-w73j
    </References>
</Vulnerability>