<Vulnerability name="CVE-2026-77410">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-09-16T14:39:08</PublicDate>
    <Bugzilla id="2535500" url="https://bugzilla.redhat.com/show_bug.cgi?id=2535500" xml:lang="en:us">
github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation
    </Bugzilla>
    <CVSS3 status="verified">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation to the negotiated Connection.Config.FrameSize value. A malicious or compromised broker can send an extreme declared body size and cause the Go runtime to attempt a correspondingly large allocation before body data is received. The allocation can exhaust memory and terminate the client process. This issue is fixed in version 1.13.0.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in RabbitMQ amqp091-go. A malicious or compromised broker can send an extreme declared message body size to a client. This causes the client to attempt an excessively large memory allocation without proper size capping, leading to memory exhaustion and termination of the client process. This vulnerability results in a Denial of Service (DoS).
    </Details>
    <AffectedRelease cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <ReleaseDate>2026-09-16T00:00:00Z</ReleaseDate>
        <Advisory type="RHSA" url="https://access.redhat.com/errata/RHSA-2026:68290">RHSA-2026:68290</Advisory>
        <Package name="opentelemetry-collector-contrib-main">opentelemetry-collector-contrib-main-0.161.0-0.1.hum1</Package>
    </AffectedRelease>
    <PackageState cpe="cpe:/a:redhat:cryostat:4">
        <ProductName>Cryostat 4</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>cryostat/cryostat-storage-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openshift_custom_metrics_autoscaler:2">
        <ProductName>Custom Metric Autoscaler operator for Red Hat Openshift</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:multicluster_globalhub">
        <ProductName>Multicluster Global Hub</ProductName>
        <FixState>Affected</FixState>
        <PackageName>multicluster-globalhub/multicluster-globalhub-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:serverless:1">
        <ProductName>OpenShift Serverless</ProductName>
        <FixState>Affected</FixState>
        <PackageName>openshift-serverless-1/kn-plugin-event-sender-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>redhat-user-workloads/grafana-acm-213</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>redhat-user-workloads/volsync-0-12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>redhat-user-workloads/volsync-bundle-0-12</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhacm2/acm-grafana-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-operator-bundle</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:acm:2">
        <ProductName>Red Hat Advanced Cluster Management for Kubernetes 2</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>rhacm2/volsync-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:openstack:18.0">
        <ProductName>Red Hat OpenStack Platform 18.0</ProductName>
        <FixState>Affected</FixState>
        <PackageName>rhoso-operators/rabbitmq-cluster-rhel9-operator</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel8</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Affected</FixState>
        <PackageName>quay/clair-rhel9</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/a:redhat:quay:3">
        <ProductName>Red Hat Quay 3</ProductName>
        <FixState>Under investigation</FixState>
        <PackageName>redhat-user-workloads/quay-clair-v3-9</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-77410
https://nvd.nist.gov/vuln/detail/CVE-2026-77410
https://github.com/rabbitmq/amqp091-go/commit/91b65fa0096a99a580cf51a31b24028ff1c60382
https://github.com/rabbitmq/amqp091-go/pull/346
https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-r9c8-gcjp-xfwh
    </References>
</Vulnerability>