CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid ProtonJ2to a version that resolves this vulnerability.Fixed in 1.2.0 - Compensating control
If immediate upgrade is not possible, reduce exposure of Apache Qpid ProtonJ2 pre-authentication endpoints to the internet (e.g., restrict access at the network/firewall to only trusted sources) until upgraded to 1.2.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67589?
CVE-2026-67589 has a risk rating of 32, indicating a moderate severity level.
How do I fix CVE-2026-67589?
To fix CVE-2026-67589, users should upgrade to version 1.2.0 of Apache Qpid ProtonJ2.
What types of attacks are possible with CVE-2026-67589?
CVE-2026-67589 can potentially allow pre-authentication attackers to cause excessive allocation, leading to denial of service.
Which versions of Apache Qpid ProtonJ2 are impacted by CVE-2026-67589?
CVE-2026-67589 affects versions of Apache Qpid ProtonJ2 through 1.1.0.
Is CVE-2026-67589 a local or remote vulnerability?
CVE-2026-67589 is a remote vulnerability that can be exploited by attackers without authentication.