Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rabbitmq
Rabbitmq amqp091-go |
|
| Vendors & Products |
Rabbitmq
Rabbitmq amqp091-go |
Wed, 16 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0. | |
| Title | RabbitMQ amqp091-go: Missing Explicit TLS Minimum Version Configuration In URI Parser | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-16T14:42:08.670Z
Reserved: 2026-08-20T19:55:27.023Z
Link: CVE-2026-77405
No data.
Status : Received
Published: 2026-09-16T15:17:47.980
Modified: 2026-09-16T15:17:47.980
Link: CVE-2026-77405
No data.
OpenCVE Enrichment
Updated: 2026-09-16T16:30:07Z