Apache Qpid security advisories
Security information for Apache Qpid
Reporting
Do you want disclose a potential security issue for Apache Qpid? Send your report to the Apache Security Team.
Advisories
This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org
Unbounded echo flow responses can lead to denial of service
CVE-2026-68080 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:51:18.656Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Unable to govern the maximum number of transfer frames per incoming delivery
CVE-2026-68078 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:43:32.321Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Unbounded disposition range handling can lead to denial of service
CVE-2026-68077 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:41:03.741Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Incoming session flow control window can be exceeded
CVE-2026-68075 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:35:58.182Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Unbounded symbol value caching can lead to pre-authentication resource exhaustion
CVE-2026-68074 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:19:51.744Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Unbounded type nesting can lead to pre-authentication stack overflow
CVE-2026-68073 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:32:20.617Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Type size/count handling can lead to excessive allocation pre-authentication
CVE-2026-68060 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:26:23.306Z
Affected
- Apache Qpid Broker-J through 10.0.1
Description
References
Unable to govern the maximum number of transfer frames per incoming delivery
CVE-2026-67592 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:44:14.457Z
Affected
- Apache Qpid ProtonJ2 through 1.1.0
Description
References
Incoming session flow control window can be exceeded
CVE-2026-67591 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:38:21.990Z
Affected
- Apache Qpid ProtonJ2 through 1.1.0
Description
References
Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-67590 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:33:34.406Z
Affected
- Apache Qpid ProtonJ2 through 1.1.0
Description
References
Type size/count handling can lead to excessive allocation pre-authentication
CVE-2026-67589 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:28:10.043Z
Affected
- Apache Qpid ProtonJ2 through 1.1.0
Description
References
Credits
- Apache Qpid security team (finder)
- xxy010605@gmail.com (reporter)
Unbounded symbol value caching can lead to pre-authentication resource exhaustion
CVE-2026-67588 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:21:39.842Z
Affected
- Apache Qpid ProtonJ2 through 1.1.0
Description
References
Unable to govern the maximum number of transfer frames per incoming delivery
CVE-2026-67555 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:43:53.150Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
References
Unbounded disposition range handling can lead to denial of service
CVE-2026-67554 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:41:21.799Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
References
Incoming session flow control window can be exceeded
CVE-2026-67553 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:37:23.826Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
References
Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-67552 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:32:53.769Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
References
Type size/count handling can lead to excessive allocation pre-authentication
CVE-2026-67551 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:27:20.446Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
References
Unbounded symbol value caching can lead to pre-authentication resource exhaustion
CVE-2026-67465 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:21:00.415Z
Affected
- Apache Qpid Proton Dotnet through 1.0.0
Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.
References
Unable to govern the maximum number of transfer frames per incoming delivery
CVE-2026-66277 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:42:26.473Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
References
Unbounded disposition range handling can lead to denial of service
CVE-2026-66276 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:39:26.606Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
References
Incoming session flow control window can be exceeded
CVE-2026-66275 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:34:44.424Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
References
Unbounded type nesting can lead to pre-authentication stackoverflow
CVE-2026-66274 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:29:40.499Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
References
Type size/count handling can lead to excessive allocation pre-authentication
CVE-2026-66273 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:23:28.044Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
References
Unbounded symbol value caching can lead to pre-authentication resource exhaustion
CVE-2026-66257 [CVE] [CVE json] [OSV json]
Last updated: 2026-08-05T05:17:56.848Z
Affected
- Apache Qpid Proton-J through 0.34.1
Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.