CVE-2026-67551: Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton-Dotnetto a version that resolves this vulnerability.Fixed in 1.1.0Patch CVE-2026-67551
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67551?
CVE-2026-67551 has a risk rating of 32, indicating a significant potential for impact.
How do I fix CVE-2026-67551?
To fix CVE-2026-67551, users should upgrade Apache Qpid Proton-Dotnet to version 1.1.0 or later.
What impact does CVE-2026-67551 have on systems?
CVE-2026-67551 can lead to excessive memory allocation and potential denial of service if exploited pre-authentication.
Which versions of Apache Qpid Proton-Dotnet are affected by CVE-2026-67551?
CVE-2026-67551 affects all versions of Apache Qpid Proton-Dotnet up to and including 1.0.0.
Who is primarily affected by CVE-2026-67551?
Users of Apache Qpid Proton-Dotnet prior to version 1.1.0 are primarily affected by CVE-2026-67551.