CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton-Jto a version that resolves this vulnerability.Fixed in 0.35.0Patch CVE-2026-66273
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66273?
CVE-2026-66273 has a risk score of 32, indicating a significant potential impact.
How do I fix CVE-2026-66273?
To mitigate CVE-2026-66273, upgrade Apache Qpid Proton-J to version 0.35.0 or later.
What type of attack does CVE-2026-66273 allow?
CVE-2026-66273 allows pre-authentication attackers to exploit type size/count handling and potentially cause a denial of service.
Which versions of Apache Qpid Proton-J are affected by CVE-2026-66273?
CVE-2026-66273 affects all versions of Apache Qpid Proton-J up to and including 0.34.1.
Is there a workaround for CVE-2026-66273 if I cannot upgrade immediately?
There are no specific workarounds for CVE-2026-66273, so upgrading to the fixed version is the recommended course of action.