Apache Qpid security advisories

Security information for Apache Qpid

Reporting

Do you want disclose a potential security issue for Apache Qpid? Send your report to the Apache Security Team.

Advisories

This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org

Unbounded echo flow responses can lead to denial of service

CVE-2026-68080 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:51:18.656Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Unable to govern the maximum number of transfer frames per incoming delivery

CVE-2026-68078 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:43:32.321Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Unbounded disposition range handling can lead to denial of service

CVE-2026-68077 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:41:03.741Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Incoming session flow control window can be exceeded

CVE-2026-68075 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:35:58.182Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Unbounded symbol value caching can lead to pre-authentication resource exhaustion

CVE-2026-68074 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:19:51.744Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Unbounded type nesting can lead to pre-authentication stack overflow

CVE-2026-68073 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:32:20.617Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Type size/count handling can lead to excessive allocation pre-authentication

CVE-2026-68060 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:26:23.306Z

Affected

  • Apache Qpid Broker-J through 10.0.1

Description

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References

Unable to govern the maximum number of transfer frames per incoming delivery

CVE-2026-67592 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:44:14.457Z

Affected

  • Apache Qpid ProtonJ2 through 1.1.0

Description

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue

References

Incoming session flow control window can be exceeded

CVE-2026-67591 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:38:21.990Z

Affected

  • Apache Qpid ProtonJ2 through 1.1.0

Description

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.

References

Unbounded type nesting can lead to pre-authentication stackoverflow

CVE-2026-67590 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:33:34.406Z

Affected

  • Apache Qpid ProtonJ2 through 1.1.0

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.

References

Type size/count handling can lead to excessive allocation pre-authentication

CVE-2026-67589 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:28:10.043Z

Affected

  • Apache Qpid ProtonJ2 through 1.1.0

Description

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.

References

Credits

Unbounded symbol value caching can lead to pre-authentication resource exhaustion

CVE-2026-67588 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:21:39.842Z

Affected

  • Apache Qpid ProtonJ2 through 1.1.0

Description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.

References

Unable to govern the maximum number of transfer frames per incoming delivery

CVE-2026-67555 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:43:53.150Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.

References

Unbounded disposition range handling can lead to denial of service

CVE-2026-67554 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:41:21.799Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.

References

Incoming session flow control window can be exceeded

CVE-2026-67553 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:37:23.826Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.

References

Unbounded type nesting can lead to pre-authentication stackoverflow

CVE-2026-67552 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:32:53.769Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue

References

Type size/count handling can lead to excessive allocation pre-authentication

CVE-2026-67551 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:27:20.446Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.

References

Unbounded symbol value caching can lead to pre-authentication resource exhaustion

CVE-2026-67465 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:21:00.415Z

Affected

  • Apache Qpid Proton Dotnet through 1.0.0

Description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1.1.0, which fixes the issue.

References

Unable to govern the maximum number of transfer frames per incoming delivery

CVE-2026-66277 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:42:26.473Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References

Unbounded disposition range handling can lead to denial of service

CVE-2026-66276 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:39:26.606Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References

Incoming session flow control window can be exceeded

CVE-2026-66275 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:34:44.424Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References

Unbounded type nesting can lead to pre-authentication stackoverflow

CVE-2026-66274 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:29:40.499Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References

Type size/count handling can lead to excessive allocation pre-authentication

CVE-2026-66273 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:23:28.044Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References

Unbounded symbol value caching can lead to pre-authentication resource exhaustion

CVE-2026-66257 [CVE] [CVE json] [OSV json]

Last updated: 2026-08-05T05:17:56.848Z

Affected

  • Apache Qpid Proton-J through 0.34.1

Description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

References