<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T09:09:21.308340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-kv65948</id>
    <title>CLEANSTART-2026-KV65948 — RabbitMQ amqp091-go is a Go AMQP 0</title>
    <updated>2026-10-07T09:09:21.311530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: opentelemetry-collector-contrib</p>
<p>Security vulnerability affects the opentelemetry-collector-contrib package. RabbitMQ amqp091-go is a Go AMQP 0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-kv65948"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-369596</id>
    <title>EUVD-2026-369596</title>
    <updated>2026-10-07T09:09:21.311576+00:00</updated>
    <content>EUVD-2026-369596</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-369596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77408</id>
    <title>fkie_cve-2026-77408</title>
    <updated>2026-10-07T09:09:21.311592+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application that accepts an oversized CorrelationId, ReplyTo, MessageId, Expiration, UserId, AppId, ContentType, ContentEncoding, or Type value can therefore serialize a wrapped length and only a truncated prefix, while reporting no error. The resulting silent metadata corruption can break request and reply correlation, routing, tracing, and downstream message processing. This issue is fixed in version 1.13.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-77408"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j497-x9hr-x34x</id>
    <title>GHSA-j497-x9hr-x34x — RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow</title>
    <updated>2026-10-07T09:09:21.311617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/rabbitmq/amqp091-go</p>
<p>## Summary
A data integrity and protocol corruption vulnerability exists in the AMQP client's property serialization logic. When encoding AMQP short string (`shortstr`) fields—such as identifiers, routing strings, and content metadata—the length of the string is explicitly cast to a fixed-size 8-bit unsigned integer (`uint8`).</p>
<p>If an application provides a property string exceeding 255 bytes, the length counter silently wraps around (e.g., a length of 300 wraps to 44). As a result, the parser writes only a truncated portion of the string into the outgoing connection buffer without returning an error. This leads to silent data corruption, broken RPC routing, and unpredictable broker-side state behavior.</p>
<p>---</p>
<p>## Vulnerability Details</p>
<p>### Mechanism
The vulnerability resides in the wire-level serialization logic for application publishing properties:</p>
<p>```go
// write.go:246
length := uint8(len(b))  // wraps silently when len(b) &gt; 255 (e.g., 300 -&gt; 44)
```</p>
<p>Because Go allows silent integer truncation during explicit type casting, lengths larger than $2^8 - 1$ lose their most significant bits. The underlying stream writer reads `length` to determine how many bytes to pull from the buffer. Because no error or boundary check accompanies this truncation, the application believes the full payload was transmitted successfully.</p>
<p>### Affected Properties
This truncation behavior affects every standard AMQP field serialized as a `shortstr`:
* `CorrelationId`
* `ReplyTo`
* `MessageId`
* `…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j497-x9hr-x34x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-77408</id>
    <title>msrc_CVE-2026-77408 — RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow</title>
    <updated>2026-10-07T09:09:21.311666+00:00</updated>
    <content>msrc_CVE-2026-77408</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-77408"/>
  </entry>
</feed>
