CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68074?
CVE-2026-68074 has a risk rating of 45.
How do I fix CVE-2026-68074?
To fix CVE-2026-68074, upgrade Apache Qpid Broker-J to version 10.1.0 or later.
What impact does CVE-2026-68074 have on my system?
CVE-2026-68074 can lead to resource exhaustion which may cause a denial of service.
Which versions of Apache Qpid Broker-J are affected by CVE-2026-68074?
CVE-2026-68074 affects Apache Qpid Broker-J versions up to 10.0.1.
Is CVE-2026-68074 a pre-authentication vulnerability?
Yes, CVE-2026-68074 is a pre-authentication vulnerability that can be exploited without prior authentication.