CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton-Jto a version that resolves this vulnerability.Fixed in 0.35.0Patch CVE-2026-66276
Event History
Frequently Asked Questions
What is the severity of CVE-2026-66276?
CVE-2026-66276 is rated with a risk score of 26.
How do I fix CVE-2026-66276?
To fix CVE-2026-66276, upgrade Apache Qpid Proton-J to version 0.35.0 or later.
What type of attack does CVE-2026-66276 enable?
CVE-2026-66276 allows an authenticated attacker to cause a denial of service.
Which versions of Apache Qpid Proton-J are affected by CVE-2026-66276?
CVE-2026-66276 affects Apache Qpid Proton-J versions prior to 0.35.0.
What is the primary issue caused by CVE-2026-66276?
The primary issue caused by CVE-2026-66276 is excessive CPU usage due to unbounded disposition range handling.