THREAT OPS › Threat News › [GHSA] GHSA-465g-fh3v-9jw4 (high) — RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
[GHSA] GHSA-465g-fh3v-9jw4 (high) — RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
GHSA-465g-fh3v-9jw4 Severity: high CVE: CVE-2026-77404
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
## Summary A query parameter injection vulnerability exists in the AMQP client's connection URI formatting logic. When generating or parsing connection URIs, TLS-related filesystem paths (such as certificates or keys) are appended directly to
Indicators of compromise
- CVE-2026-77404cve
Original source: https://github.com/advisories/GHSA-465g-fh3v-9jw4