{"id":"GHSA-j497-x9hr-x34x","summary":"RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow","details":"## Summary\nA data integrity and protocol corruption vulnerability exists in the AMQP client's property serialization logic. When encoding AMQP short string (`shortstr`) fields—such as identifiers, routing strings, and content metadata—the length of the string is explicitly cast to a fixed-size 8-bit unsigned integer (`uint8`). \n\nIf an application provides a property string exceeding 255 bytes, the length counter silently wraps around (e.g., a length of 300 wraps to 44). As a result, the parser writes only a truncated portion of the string into the outgoing connection buffer without returning an error. This leads to silent data corruption, broken RPC routing, and unpredictable broker-side state behavior.\n\n---\n\n## Vulnerability Details\n\n### Mechanism\nThe vulnerability resides in the wire-level serialization logic for application publishing properties:\n\n```go\n// write.go:246\nlength := uint8(len(b))  // wraps silently when len(b) \u003e 255 (e.g., 300 -\u003e 44)\n```\n\nBecause Go allows silent integer truncation during explicit type casting, lengths larger than $2^8 - 1$ lose their most significant bits. The underlying stream writer reads `length` to determine how many bytes to pull from the buffer. Because no error or boundary check accompanies this truncation, the application believes the full payload was transmitted successfully.\n\n### Affected Properties\nThis truncation behavior affects every standard AMQP field serialized as a `shortstr`:\n* `CorrelationId`\n* `ReplyTo`\n* `MessageId`\n* `Expiration`\n* `UserId`\n* `AppId`\n* `ContentType`\n* `ContentEncoding`\n* `Type`\n\n### Impact\nThe critical consequence is **silent protocol desynchronization at the application layer**. The underlying TCP stream remains framed properly (because the shortened length matches the bytes written), but the business logic is corrupted. Distributed transactions, request-reply correlations, and tracing headers are truncated, causing downstream systems to drop messages or route them to incorrect consumers.\n\n---\n\n## Attack Vector\nAn attacker who can influence metadata fields processed by an upstream application (such as a user-supplied tracking ID or a long content-type header) can exploit this to break system components:\n\n1. **Targeting RPC Routing:** A user passes a malicious or overly long `CorrelationId` of 300 bytes through an application endpoint.\n2. **Silent Truncation:** The library wraps the length value to 44, transmitting only the first 44 bytes to the rabbitMQ broker.\n3. **Broken Correlation:** When the service processes the request and responds, the replying consumer attempts to route the message using the full 300-byte identifier. Because the broker only recognizes the truncated 44-byte ID, the reply loop breaks silently, leading to hanging processes or data leaks across transaction boundaries.","aliases":["CVE-2026-77408","GO-2026-6498"],"modified":"2026-10-01T20:55:54.424641007Z","published":"2026-09-17T17:04:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-17T17:04:15Z","nvd_published_at":"2026-09-16T15:17:49Z","cwe_ids":["CWE-190"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-j497-x9hr-x34x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77408"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/pull/354"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/commit/6959423aa2784a1971e399175dfb2065dea0f3b0"},{"type":"PACKAGE","url":"https://github.com/rabbitmq/amqp091-go"},{"type":"WEB","url":"https://github.com/rabbitmq/amqp091-go/releases/tag/v1.13.0"}],"affected":[{"package":{"name":"github.com/rabbitmq/amqp091-go","ecosystem":"Go","purl":"pkg:golang/github.com/rabbitmq/amqp091-go"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-j497-x9hr-x34x/GHSA-j497-x9hr-x34x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:L"}]}