Vulnerability GHSA-465g-fh3v-9jw4

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
14 days ago
September 17, 2026 at 05:03 PM UTC
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection
v1.1.0 - v1.12.0
v1.1.0 - v1.12.0

Summary

RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection

Details

Summary

A query parameter injection vulnerability exists in the AMQP client's connection URI formatting logic. When generating or parsing connection URIs, TLS-related filesystem paths (such as certificates or keys) are appended directly to the URI's query string using string concatenation rather than secure URL encoding via functions like url.QueryEscape.

If an application handles a TLS file path containing special character delimiters (such as & or =), these characters are interpreted as parameter separators by the URI parser. If the resulting URI.String() output is subsequently re-parsed via ParseURI, the injected fields can silently overwrite or hijack critical configuration parameters, forcing the client to use arbitrary connection settings or alternate TLS files.

Attack Vector

An attacker who has partial control over directory naming conventions or environmental variables used to specify local infrastructure paths can execute a parameter injection attack:

  1. Path Creation: An attacker sets up a path containing deliberate URL parameter delimiters (e.g., /var/lib/certs/client.crt?cacertfile=/tmp/fake_ca.crt&).
  2. String Generation: The application serializes the active connection state or passes the paths down to an unescaped URI builder function.
  3. Configuration Hijack: The URI string is generated with the injected parameter embedded into the query structure. When the client attempts to reuse or re-parse this connection string during a connection retry or worker spin-up, it parses the injected cacertfile parameter, loading a different, unverified Certificate Authority string.

Timeline

Published
14 days ago
September 17, 2026 at 05:03 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:56 PM UTC