THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rm6m-hrcw-jw33 (high) — RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

[GHSA] GHSA-rm6m-hrcw-jw33 (high) — RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

medgithub_advisoriesPublished 2026-09-17

GHSA-rm6m-hrcw-jw33 Severity: high CVE: CVE-2026-77406

RabbitMQ amqp091-go: Consumer Message Flooding via Signed-to-Unsigned Integer Casting in Qos Configuration

## Summary A logic and resource exhaustion vulnerability exists in the AMQP client's Quality of Service (`Qos`) configuration method. The `Qos` function accepts signed integers (`int`) for the `prefetchCount` and `prefetchSize` paramete

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rm6m-hrcw-jw33