VDB

CVE-2026-79921

CVE-2026-79921 PUBLISHED CVSS 8.9 HIGH

Reported by GitHub_M · Published August 26, 2026

amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints. Version 1.13.0 contains a fix. No known workarounds are available.

Risk Scores

CVSS 4.0
8.9
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Affected Products

VendorProductVersions
rabbitmqamqp091-go< 1.13.0
chainguardminio0, 0, 0
wolfifalcosidekick0, 0, 0
rabbitmqamqp091-go< 1.13.0, < 1.13.0, < 1.13.0
chainguarddapr-fips-1.180, 0
chainguardtrufflehog0, 0, 0
chainguardkeda-fips-2.200, 0
chainguardbento0, 0, 0
chainguardopentelemetry-collector-contrib0, 0, 0
chainguarddapr-fips-1.150
wolfitelegraf-1.370, 0
chainguarddapr-1.170, 0
wolfitrufflehog0, 0, 0
wolfiguac0, 0, 0
wolfiargo-events0, 0, 0
chainguardkeda-2.180, 0
chainguardtrufflehog-fips0, 0, 0
wolfitelegraf-1.380, 0, 0
wolfiopentelemetry-collector-contrib0, 0, 0
chainguarddapr-1.180, 0

…and 33 more

Timeline

  • Aug 26, 2026 CVE Published
  • Aug 27, 2026 EPSS Score
  • Aug 29, 2026 CVE Updated
  • Sep 2, 2026 EPSS Score
  • Sep 2, 2026 Security Advisory
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›