CVE-2026-67590: Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid ProtonJ2to a version that resolves this vulnerability.Fixed in 1.2.0Patch CVE-2026-67590
Event History
Frequently Asked Questions
What is the severity of CVE-2026-67590?
CVE-2026-67590 has a risk score of 28, indicating a significant vulnerability.
How do I fix CVE-2026-67590?
To fix CVE-2026-67590, upgrade Apache Qpid ProtonJ2 to version 1.2.0 or later.
What can an attacker do with CVE-2026-67590?
An attacker could leverage type nesting to cause a StackOverflowError, potentially leading to a denial of service.
Which versions of Apache Qpid ProtonJ2 are affected by CVE-2026-67590?
CVE-2026-67590 affects Apache Qpid ProtonJ2 versions up to and including 1.1.0.
When was CVE-2026-67590 published?
CVE-2026-67590 was published on August 4, 2026.