CVE-2026-67555: Apache Qpid Proton Dotnet: Unable to govern the maximum number of transfer frames per incoming delivery
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service
This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.
Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Proton-Dotnetto a version that resolves this vulnerability.Fixed in 1.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67555?
CVE-2026-67555 has a risk rating of 26, indicating a critical potential for resource exhaustion leading to denial of service.
How do I fix CVE-2026-67555?
To mitigate CVE-2026-67555, users should upgrade to Apache Qpid Proton-Dotnet version 1.1 or later.
What impact does CVE-2026-67555 have on my system?
CVE-2026-67555 allows authenticated attackers to exploit resource usage, potentially leading to service disruptions.
Which versions of Apache Qpid Proton Dotnet are affected by CVE-2026-67555?
CVE-2026-67555 affects Apache Qpid Proton-Dotnet versions prior to 1.1.0.
Who is at risk from CVE-2026-67555?
Users of Apache Qpid Proton-Dotnet versions up to 1.0.0 are at risk of exploitation related to CVE-2026-67555.