diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch
new file mode 100644
index 0000000000..4f55d99c71
--- /dev/null
+++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-44235.patch
@@ -0,0 +1,93 @@
+From db957b8cdc980e4226b6cd6f18061eabfc8f409e Mon Sep 17 00:00:00 2001
+From: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+Date: Fri, 9 Oct 2026 07:02:33 +0000
+Subject: [PATCH] rabbitmq-c: patch CVE-2026-44235
+
+size_t underflow in AMQP frame length computation leads to an
+out-of-bounds read in rabbitmq-c.
+
+A malicious AMQP server can send an AMQP frame whose stated body is
+shorter than the per-frame-type header it claims to carry.
+amqp_handle_input() then computed encoded.len without a lower-bound
+check on target_size. Because encoded.len is a size_t, the
+subtraction wrapped to a value near SIZE_MAX. The bogus length was
+passed to the method/properties and table decoders, whose bounds
+checks could no longer constrain the parser, causing an
+out-of-bounds read and client-side crash during amqp_login.
+
+Validate target_size against the minimum required for each frame
+type and return AMQP_STATUS_BAD_AMQP_DATA when the frame is too
+small, before computing encoded.len.
+
+Details:
+https://nvd.nist.gov/vuln/detail/CVE-2026-44235
+
+CVE: CVE-2026-44235
+
+Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1d3afbb056fee5cc9ea05680bf32288715d0d802]
+
+Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+---
+ .../input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw | Bin 0 -> 113 bytes
+ librabbitmq/amqp_connection.c                 |  19 ++++++++++++++++++
+ 2 files changed, 19 insertions(+)
+ create mode 100644 fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw
+
+diff --git a/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw b/fuzz/input/fuzz_server_ghsa-9mmv-r8g3-qp46.raw
+new file mode 100644
+index 0000000000000000000000000000000000000000..558e9f5bff6b24ad3104b8a3038ab5b271257dcc
+GIT binary patch
+literal 113
+zcmZQ%0D&+DE+FItvaHO#6&U^l0azR#5qxj8*#?Ay5=J1KHNeNw(+|W*&5I8WKF0)>
+L=Vq{ht2+k({(TL>
+
+literal 0
+HcmV?d00001
+
+diff --git a/librabbitmq/amqp_connection.c b/librabbitmq/amqp_connection.c
+index 56ab8a8..4326ef7 100644
+--- a/librabbitmq/amqp_connection.c
++++ b/librabbitmq/amqp_connection.c
+@@ -320,6 +320,13 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+ 
+       switch (decoded_frame->frame_type) {
+         case AMQP_FRAME_METHOD:
++          /* A METHOD frame body must contain at least the 4-byte method id.
++           * Reject undersized frames before subtracting from target_size to
++           * avoid an unsigned underflow that would yield a huge encoded.len
++           * and cause out-of-bounds reads in amqp_decode_method(). */
++          if (state->target_size < HEADER_SIZE + 4 + FOOTER_SIZE) {
++            return AMQP_STATUS_BAD_AMQP_DATA;
++          }
+           decoded_frame->payload.method.id =
+               amqp_d32(amqp_offset(raw_frame, HEADER_SIZE));
+           encoded.bytes = amqp_offset(raw_frame, HEADER_SIZE + 4);
+@@ -335,6 +342,15 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+           break;
+ 
+         case AMQP_FRAME_HEADER:
++          /* A HEADER frame body must contain at least 12 bytes (class_id,
++           * weight, body_size). Reject undersized frames before subtracting
++           * from target_size to avoid an unsigned underflow that would yield
++           * a huge encoded.len and cause out-of-bounds reads in
++           * amqp_decode_properties() / the table decoder
++           * (CVE: GHSA-9mmv-r8g3-qp46). */
++          if (state->target_size < HEADER_SIZE + 12 + FOOTER_SIZE) {
++            return AMQP_STATUS_BAD_AMQP_DATA;
++          }
+           decoded_frame->payload.properties.class_id =
+               amqp_d16(amqp_offset(raw_frame, HEADER_SIZE));
+           /* unused 2-byte weight field goes here */
+@@ -354,6 +370,9 @@ int amqp_handle_input(amqp_connection_state_t state, amqp_bytes_t received_data,
+           break;
+ 
+         case AMQP_FRAME_BODY:
++          if (state->target_size < HEADER_SIZE + FOOTER_SIZE) {
++            return AMQP_STATUS_BAD_AMQP_DATA;
++          }
+           decoded_frame->payload.body_fragment.len =
+               state->target_size - HEADER_SIZE - FOOTER_SIZE;
+           decoded_frame->payload.body_fragment.bytes =
+-- 
+2.35.5
+
diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
index b8bc5b57e3..afdc99623a 100644
--- a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
+++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
@@ -5,6 +5,7 @@ LICENSE = "MIT"
 
 SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \
 	   file://CVE-2026-61547.patch \
+           file://CVE-2026-44235.patch \
 "
 SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8"
 
