Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4658-1 | librabbitmq security update |
Debian DSA |
DSA-6343-1 | librabbitmq security update |
Ubuntu USN |
USN-8437-1 | rabbitmq-c vulnerabilities |
Ubuntu USN |
USN-8724-1 | rabbitmq-c vulnerabilities |
Thu, 17 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in librabbitmq/amqp_socket.c. amqp_tune_connection() in librabbitmq/amqp_connection.c uses frame_max to reallocate the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. Immediate serialization of connection.tune-ok through amqp_frame_to_bytes() writes beyond the undersized heap allocation, causing memory corruption and likely denial of service. An on-path attacker can also trigger the flaw against plaintext AMQP traffic. Code execution is theoretically possible but was not demonstrated. This issue is fixed in version 0.16.0. | |
| Title | rabbitmq-c: Heap buffer overflow in AMQP login handshake via undersized connection.tune.frame_max | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T17:04:18.803Z
Reserved: 2026-05-05T15:42:40.519Z
Link: CVE-2026-44236
No data.
Status : Received
Published: 2026-09-17T18:16:44.503
Modified: 2026-09-17T18:16:44.503
Link: CVE-2026-44236
No data.
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN