CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton Dotnet (Apache Qpid Proton-Dotnet)to a version that resolves this vulnerability.Fixed in 1.1.0Patch CVE-2026-67554
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67554?
CVE-2026-67554 has been assigned a risk score of 23, indicating a high severity level.
How do I fix CVE-2026-67554?
You can fix CVE-2026-67554 by upgrading to version 1.1.0 of Apache Qpid Proton-Dotnet.
Who is affected by CVE-2026-67554?
CVE-2026-67554 affects users of Apache Qpid Proton-Dotnet up to version 1.0.0.
What type of vulnerability is CVE-2026-67554?
CVE-2026-67554 is a denial of service vulnerability caused by unbounded disposition range handling.
Can an attacker exploit CVE-2026-67554 remotely?
Yes, an authenticated attacker can exploit CVE-2026-67554 to cause excessive CPU usage.