FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

redpanda-connect -- memory exhaustion via oversized AMQP frames

Affected packages
redpanda-connect < 4.109.0

Details

VuXML ID 5d69ee28-adb9-11f1-9d0e-4c526214c986
Discovery 2026-08-26
Entry 2026-09-11

amqp091-go developers report:

Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and process content body frames that exceed the negotiated frame_max limit. This can lead to unexpected memory consumption or application-layer denial of service (DoS), bypassing the protocol's built-in framing constraints.

Redpanda Connect vendored an affected amqp091-go release up to version 4.108.0; 4.109.0 bumps it to 1.14.0.

References

CVE Name CVE-2026-79921
URL https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp
URL https://github.com/redpanda-data/connect/pull/4795