CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68073?
CVE-2026-68073 has a risk rating of 28, indicating a significant potential impact.
How do I fix CVE-2026-68073?
To fix CVE-2026-68073, upgrade Apache Qpid Broker-J to version 10.1.0 or later.
What type of attack does CVE-2026-68073 facilitate?
CVE-2026-68073 allows a pre-authentication attacker to exploit unbounded type nesting, resulting in a potential denial of service.
Which versions of Apache Qpid Broker-J are affected by CVE-2026-68073?
Apache Qpid Broker-J versions up to 10.0.1 are affected by CVE-2026-68073.
What is the primary consequence of CVE-2026-68073?
The primary consequence of CVE-2026-68073 is a StackOverflowError that can lead to a denial of service.