CVE-2026-67552: Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton Dotnetto a version that resolves this vulnerability.Fixed in 1.1.0Patch CVE-2026-67552
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67552?
CVE-2026-67552 has a risk score of 43, indicating a significant vulnerability.
What vulnerability does CVE-2026-67552 describe?
CVE-2026-67552 describes an unbounded type nesting issue in Apache Qpid Proton Dotnet that can lead to a pre-authentication StackOverflowError.
How do I fix CVE-2026-67552?
To fix CVE-2026-67552, users are advised to upgrade to Apache Qpid Proton-Dotnet version 1.1.0 or later.
What could an attacker exploit in CVE-2026-67552?
An attacker could exploit CVE-2026-67552 by leveraging type nesting to trigger a StackOverflowError and potentially cause a denial of service.
Which version of Apache Qpid Proton Dotnet is affected by CVE-2026-67552?
CVE-2026-67552 affects versions of Apache Qpid Proton Dotnet up to and including 1.0.0.