THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-465g-fh3v-9jw4 (high) — RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

[GHSA] GHSA-465g-fh3v-9jw4 (high) — RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

medgithub_advisoriesPublished 2026-09-17

GHSA-465g-fh3v-9jw4 Severity: high CVE: CVE-2026-77404

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

## Summary A query parameter injection vulnerability exists in the AMQP client's connection URI formatting logic. When generating or parsing connection URIs, TLS-related filesystem paths (such as certificates or keys) are appended directly to

Indicators of compromise

Original source: https://github.com/advisories/GHSA-465g-fh3v-9jw4