CVE-2026-67588: Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid ProtonJ2to a version that resolves this vulnerability.Fixed in 1.2.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67588?
The severity of CVE-2026-67588 is rated at 45.
How do I fix CVE-2026-67588?
To fix CVE-2026-67588, users should upgrade to Apache Qpid ProtonJ2 version 1.2.0.
What kind of attack does CVE-2026-67588 allow?
CVE-2026-67588 allows a pre-authentication attack that can lead to resource exhaustion and denial of service.
Which versions of Apache Qpid ProtonJ2 are affected by CVE-2026-67588?
Apache Qpid ProtonJ2 versions prior to 1.2.0 are affected by CVE-2026-67588.
What impact does CVE-2026-67588 have on users?
CVE-2026-67588 can lead to denial of service due to unbounded symbol value caching.