diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-59986.patch b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-59986.patch
new file mode 100644
index 0000000000..1b316c1d11
--- /dev/null
+++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c/CVE-2026-59986.patch
@@ -0,0 +1,173 @@
+From 0977b4326649b323fa3418bec8e46398f18dcc30 Mon Sep 17 00:00:00 2001
+From: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+Date: Fri, 9 Oct 2026 10:37:17 +0000
+Subject: [PATCH] rabbitmq-c: fix CVE-2026-59986
+
+size_t integer overflow in amqp_decode_bytes bypasses a bounds
+check on 32-bit systems, leading to an out-of-bounds read.
+
+The bounds check in amqp_decode_bytes computed (offset + len) and
+compared it against the buffer length. When offset + len exceeds
+SIZE_MAX the addition wraps around, which an attacker can trigger
+on 32-bit platforms by supplying a large BYTES/UTF8 wire length
+(len is read from the AMQP frame as a uint32_t). The wrap made
+the check pass and produced an amqp_bytes_t with a multi-gigabyte
+length pointing into a small frame buffer, leading to an
+out-of-bounds read (information disclosure or crash) when the
+value was later processed.
+
+Rewrite the check to compare len against the remaining space
+(len <= encoded.len - offset) which cannot overflow because
+offset is always <= encoded.len. Apply the same hardening to
+amqp_encode_bytes for consistency. Add a regression test.
+
+Details:
+https://nvd.nist.gov/vuln/detail/CVE-2026-59986
+
+CVE: CVE-2026-59986
+
+Upstream-Status: Backport [https://github.com/alanxz/rabbitmq-c/commit/1bb1b9b1b7bc69eede6295e95fa9527c731f0798]
+
+Signed-off-by: Poornima Lokesh <Poornima.Lokesh@windriver.com>
+---
+ librabbitmq/amqp_private.h | 12 +++++-
+ tests/CMakeLists.txt       |  4 ++
+ tests/test_decode_bytes.c  | 84 ++++++++++++++++++++++++++++++++++++++
+ 3 files changed, 98 insertions(+), 2 deletions(-)
+ create mode 100644 tests/test_decode_bytes.c
+
+diff --git a/librabbitmq/amqp_private.h b/librabbitmq/amqp_private.h
+index 77a6904..93ee7f6 100644
+--- a/librabbitmq/amqp_private.h
++++ b/librabbitmq/amqp_private.h
+@@ -299,7 +299,10 @@ static inline int amqp_encode_bytes(amqp_bytes_t encoded, size_t *offset,
+   if (input.len == 0) {
+     return 1;
+   }
+-  if ((*offset = o + input.len) <= encoded.len) {
++  *offset = o + input.len;
++  /* Compare against remaining space rather than o + input.len to avoid size_t
++   * overflow; o <= encoded.len, so encoded.len - o cannot underflow. */
++  if (o <= encoded.len && input.len <= encoded.len - o) {
+     memcpy(amqp_offset(encoded.bytes, o), input.bytes, input.len);
+     return 1;
+   } else {
+@@ -310,7 +313,12 @@ static inline int amqp_encode_bytes(amqp_bytes_t encoded, size_t *offset,
+ static inline int amqp_decode_bytes(amqp_bytes_t encoded, size_t *offset,
+                                     amqp_bytes_t *output, size_t len) {
+   size_t o = *offset;
+-  if ((*offset = o + len) <= encoded.len) {
++  *offset = o + len;
++  /* Compare against remaining space rather than o + len: with len read from the
++   * wire (uint32_t), o + len can overflow size_t on 32-bit platforms and wrap
++   * past the check, yielding an out-of-bounds amqp_bytes_t. o <= encoded.len,
++   * so encoded.len - o cannot underflow. */
++  if (o <= encoded.len && len <= encoded.len - o) {
+     output->bytes = amqp_offset(encoded.bytes, o);
+     output->len = len;
+     return 1;
+diff --git a/tests/CMakeLists.txt b/tests/CMakeLists.txt
+index 8c0aee0..edff2e5 100644
+--- a/tests/CMakeLists.txt
++++ b/tests/CMakeLists.txt
+@@ -41,3 +41,7 @@ add_executable(test_merge_capabilities test_merge_capabilities.c)
+ target_link_libraries(test_merge_capabilities rabbitmq-static)
+ add_test(merge_capabilities test_merge_capabilities)
+ 
++
++add_executable(test_decode_bytes test_decode_bytes.c)
++target_link_libraries(test_decode_bytes rabbitmq-static)
++add_test(decode_bytes test_decode_bytes)
+diff --git a/tests/test_decode_bytes.c b/tests/test_decode_bytes.c
+new file mode 100644
+index 0000000..17309f6
+--- /dev/null
++++ b/tests/test_decode_bytes.c
+@@ -0,0 +1,84 @@
++// Copyright 2007 - 2021, Alan Antonuk and the rabbitmq-c contributors.
++// SPDX-License-Identifier: mit
++
++#include <stdint.h>
++#include <stdio.h>
++#include <stdlib.h>
++
++#include "amqp_private.h"
++
++/* Regression test for GHSA-jgjf-7fwf-f3c7: a size_t integer overflow in
++ * amqp_decode_bytes bypassed the bounds check on 32-bit systems, producing an
++ * out-of-bounds amqp_bytes_t (information disclosure / crash). The check must
++ * reject any (offset, len) pair that would read past the end of the buffer,
++ * including ones where offset + len wraps around SIZE_MAX. */
++
++static int failures = 0;
++
++static void expect_reject(const char *name, amqp_bytes_t encoded, size_t offset,
++                          size_t len) {
++  amqp_bytes_t output;
++  size_t off = offset;
++  output.bytes = NULL;
++  output.len = 0;
++  if (amqp_decode_bytes(encoded, &off, &output, len)) {
++    fprintf(stderr,
++            "FAIL %s: amqp_decode_bytes accepted an out-of-bounds length "
++            "(offset=%zu len=%zu buffer=%zu) -> output.len=%zu\n",
++            name, offset, len, encoded.len, output.len);
++    failures++;
++  }
++}
++
++static void expect_accept(const char *name, amqp_bytes_t encoded, size_t offset,
++                          size_t len) {
++  amqp_bytes_t output;
++  size_t off = offset;
++  output.bytes = NULL;
++  output.len = 0;
++  if (!amqp_decode_bytes(encoded, &off, &output, len)) {
++    fprintf(stderr,
++            "FAIL %s: amqp_decode_bytes rejected a valid length "
++            "(offset=%zu len=%zu buffer=%zu)\n",
++            name, offset, len, encoded.len);
++    failures++;
++    return;
++  }
++  if (output.len != len || output.bytes != amqp_offset(encoded.bytes, offset)) {
++    fprintf(stderr, "FAIL %s: amqp_decode_bytes produced wrong output\n", name);
++    failures++;
++  }
++}
++
++int main(void) {
++  char buffer[16];
++  amqp_bytes_t encoded;
++  encoded.bytes = buffer;
++  encoded.len = sizeof(buffer);
++
++  /* Normal, in-bounds decodes still work. */
++  expect_accept("full buffer", encoded, 0, sizeof(buffer));
++  expect_accept("partial at offset", encoded, 4, 8);
++  expect_accept("zero length", encoded, 8, 0);
++
++  /* Plain out-of-bounds (no overflow) is rejected. */
++  expect_reject("len past end", encoded, 0, sizeof(buffer) + 1);
++  expect_reject("offset past end", encoded, sizeof(buffer) + 1, 0);
++
++  /* The core of the advisory: a wire length large enough that offset + len
++   * wraps around SIZE_MAX. On 32-bit platforms a uint32_t length of
++   * 0xFFFFFFF5 with a small offset wraps to a tiny value; on any platform we
++   * can force the wrap with a len near SIZE_MAX. Both must be rejected rather
++   * than producing a multi-gigabyte amqp_bytes_t into a small buffer. */
++  expect_reject("overflow to zero", encoded, 11, (size_t)0 - 11);
++  expect_reject("overflow wraps small", encoded, 16, (size_t)0 - 8);
++  expect_reject("max len", encoded, 1, (size_t)-1);
++  expect_reject("32-bit style len", encoded, 11, (size_t)0xFFFFFFF5u);
++
++  if (failures) {
++    fprintf(stderr, "%d test(s) failed\n", failures);
++    return 1;
++  }
++  printf("all amqp_decode_bytes bounds tests passed\n");
++  return 0;
++}
+-- 
+2.49.1
+
diff --git a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
index afdc99623a..45a90cb7b7 100644
--- a/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
+++ b/meta-oe/recipes-connectivity/rabbitmq-c/rabbitmq-c_0.15.0.bb
@@ -6,6 +6,7 @@ LICENSE = "MIT"
 SRC_URI = "git://github.com/alanxz/rabbitmq-c.git;branch=master;protocol=https \
 	   file://CVE-2026-61547.patch \
            file://CVE-2026-44235.patch \
+           file://CVE-2026-59986.patch \
 "
 SRCREV = "84b81cd97a1b5515d3d4b304796680da24c666d8"
 
