BIT-rabbitmq-c-2026-44236

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/rabbitmq-c/BIT-rabbitmq-c-2026-44236.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-rabbitmq-c-2026-44236
Aliases
Published
2026-09-29T08:56:07Z
Modified
2026-09-29T10:10:41Z
Summary
rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max
Details

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0.

Database specific
{
    "cpes": [
        "cpe:2.3:a:rabbitmq-c_project:rabbitmq-c:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / rabbitmq-c

Package

Name
rabbitmq-c
Purl
pkg:bitnami/rabbitmq-c

Severity

  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.16.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/rabbitmq-c/BIT-rabbitmq-c-2026-44236.json"