git: 387596fa7d6b - main - security/vuxml: Document redpanda-connect vulnerability

From: Jimmy Olgeni <olgeni_at_FreeBSD.org>
Date: Fri, 11 Sep 2026 08:31:13 UTC
The branch main has been updated by olgeni:

URL: https://cgit.FreeBSD.org/ports/commit/?id=387596fa7d6b12b87677b158ca968fab3c1f95e0

commit 387596fa7d6b12b87677b158ca968fab3c1f95e0
Author:     Jimmy Olgeni <olgeni@FreeBSD.org>
AuthorDate: 2026-09-11 08:24:35 +0000
Commit:     Jimmy Olgeni <olgeni@FreeBSD.org>
CommitDate: 2026-09-11 08:30:33 +0000

    security/vuxml: Document redpanda-connect vulnerability
---
 security/vuxml/vuln/2026.xml | 34 ++++++++++++++++++++++++++++++++++
 1 file changed, 34 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 02d171104e06..bb8982eb5958 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,37 @@
+  <vuln vid="5d69ee28-adb9-11f1-9d0e-4c526214c986">
+    <topic>redpanda-connect -- memory exhaustion via oversized AMQP frames</topic>
+    <affects>
+	<package>
+	  <name>redpanda-connect</name>
+	  <range><lt>4.109.0</lt></range>
+	</package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>amqp091-go developers report:</p>
+	<blockquote cite="https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp">
+	  <p>Before version 1.13.0, a compromised or malicious AMQP broker
+	    can force the client to allocate resources for and process
+	    content body frames that exceed the negotiated frame_max limit.
+	    This can lead to unexpected memory consumption or
+	    application-layer denial of service (DoS), bypassing the
+	    protocol's built-in framing constraints.</p>
+	</blockquote>
+	<p>Redpanda Connect vendored an affected amqp091-go release
+	  up to version 4.108.0; 4.109.0 bumps it to 1.14.0.</p>
+	</body>
+    </description>
+    <references>
+      <cvename>CVE-2026-79921</cvename>
+      <url>https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp</url>
+      <url>https://github.com/redpanda-data/connect/pull/4795</url>
+    </references>
+    <dates>
+      <discovery>2026-08-26</discovery>
+      <entry>2026-09-11</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="9736fef3-ada6-11f1-a655-3497f65b111b">
     <topic>FreeIPA -- multiple vulnerabilities</topic>
     <affects>