CVE-2026-67465: Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton Dotnet (Proton-Dotnet)to a version that resolves this vulnerability.Fixed in 1.1.0Patch CVE-2026-67465
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67465?
The severity of CVE-2026-67465 is rated at risk level 36.
How do I fix CVE-2026-67465?
To fix CVE-2026-67465, upgrade Apache Qpid Proton Dotnet to version 1.1.0.
What type of vulnerability is CVE-2026-67465?
CVE-2026-67465 is a denial of service vulnerability due to unbounded symbol value caching.
Who is affected by CVE-2026-67465?
CVE-2026-67465 affects all users of Apache Qpid Proton Dotnet versions prior to 1.1.0.
How does the attack vector work for CVE-2026-67465?
An attacker can exploit CVE-2026-67465 by leveraging unbounded symbol value caching to cause resource exhaustion before authentication.