CVE-2026-77405EPSS p18.8%
CVE-2026-77405CVE-2026-77405
Description
RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can therefore negotiate an obsolete protocol version when connecting through an amqps URI. A network attacker able to influence TLS negotiation with such a legacy build may weaken transport protection for AMQP messages and credentials. This issue is fixed in version 1.13.0.
Scoring
| EPSS | 0.28% probability of exploitation · percentile 18.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-24 |