<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 05:50:13 +0000</lastBuildDate>
    <item>
      <title>CLEANSTART-2026-AD74285 — RabbitMQ amqp091-go is a Go AMQP 0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ad74285</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opentelemetry-collector-contrib&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the opentelemetry-collector-contrib package. RabbitMQ amqp091-go is a Go AMQP 0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: opentelemetry-collector-contrib&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the opentelemetry-collector-contrib package. RabbitMQ amqp091-go is a Go AMQP 0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ad74285</guid>
    </item>
    <item>
      <title>EUVD-2026-372225</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372225</link>
      <description>EUVD-2026-372225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372225</guid>
    </item>
    <item>
      <title>fkie_cve-2026-77405</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-77405</link>
      <description>&lt;p&gt;RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-77405</guid>
    </item>
    <item>
      <title>GHSA-33mj-cw25-m34h — RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-33mj-cw25-m34h</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rabbitmq/amqp091-go&lt;/p&gt;
&lt;p&gt;## Summary
A structural security weakness exists in the AMQP client&amp;#39;s TLS configuration generator (`tlsConfigFromURI`). When constructing a `*tls.Config` object from an `amqps://` connection URI, the library initializes the structure without explicitly defining the `MinVersion` field.&lt;/p&gt;
&lt;p&gt;While modern versions of the Go compiler toolchain (Go 1.18+) default the implicit minimum version to TLS 1.2, this security posture relies entirely on an implicit toolchain dependency. If the library is compiled using legacy Go toolchains (Go &amp;lt; 1.18), or if a future toolchain introduces fallback behavior, the client could silently negotiate obsolete and insecure TLS 1.0 or TLS 1.1 protocols during connection handshakes with a compromised or malicious AMQP broker.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability lies in the lack of an explicit safety floor when assigning configurations inside the URI component:&lt;/p&gt;
&lt;p&gt;```go
// Example within uri.go&amp;#39;s tlsConfigFromURI
cfg := &amp;amp;tls.Config{
    ServerName: host,
    // MinVersion is left completely unassigned (defaults to 0, or toolchain default)
}
```&lt;/p&gt;
&lt;p&gt;In the Go standard library (`crypto/tls`), leaving `MinVersion: 0` instructs the runtime to choose the toolchain&amp;#39;s default minimum. Prior to Go 1.18, this default allowed negotiation down to TLS 1.0. Relying on implicit compiler configurations violates secure coding practices by decoupling the library&amp;#39;s security posture from its source code, leaving applications vulnerable based solely on…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/rabbitmq/amqp091-go&lt;/p&gt;
&lt;p&gt;## Summary
A structural security weakness exists in the AMQP client&amp;#39;s TLS configuration generator (`tlsConfigFromURI`). When constructing a `*tls.Config` object from an `amqps://` connection URI, the library initializes the structure without explicitly defining the `MinVersion` field.&lt;/p&gt;
&lt;p&gt;While modern versions of the Go compiler toolchain (Go 1.18+) default the implicit minimum version to TLS 1.2, this security posture relies entirely on an implicit toolchain dependency. If the library is compiled using legacy Go toolchains (Go &amp;lt; 1.18), or if a future toolchain introduces fallback behavior, the client could silently negotiate obsolete and insecure TLS 1.0 or TLS 1.1 protocols during connection handshakes with a compromised or malicious AMQP broker.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Details&lt;/p&gt;
&lt;p&gt;### Mechanism
The vulnerability lies in the lack of an explicit safety floor when assigning configurations inside the URI component:&lt;/p&gt;
&lt;p&gt;```go
// Example within uri.go&amp;#39;s tlsConfigFromURI
cfg := &amp;amp;tls.Config{
    ServerName: host,
    // MinVersion is left completely unassigned (defaults to 0, or toolchain default)
}
```&lt;/p&gt;
&lt;p&gt;In the Go standard library (`crypto/tls`), leaving `MinVersion: 0` instructs the runtime to choose the toolchain&amp;#39;s default minimum. Prior to Go 1.18, this default allowed negotiation down to TLS 1.0. Relying on implicit compiler configurations violates secure coding practices by decoupling the library&amp;#39;s security posture from its source code, leaving applications vulnerable based solely on…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-33mj-cw25-m34h</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-77405 — RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-77405</link>
      <description>msrc_CVE-2026-77405</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-77405</guid>
    </item>
  </channel>
</rss>
