CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.0Patch CVE-2026-68077
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68077?
The severity of CVE-2026-68077 is rated at risk level 23, indicating a significant potential for impact.
How do I fix CVE-2026-68077?
To fix CVE-2026-68077, users should upgrade to Apache Qpid Broker-J version 10.1.0 or higher.
What type of attack does CVE-2026-68077 enable?
CVE-2026-68077 enables an authenticated attacker to cause denial of service through excessive CPU usage.
Which software is impacted by CVE-2026-68077?
CVE-2026-68077 affects Apache Qpid Broker-J versions through 10.0.1.
What is the cause of the vulnerability in CVE-2026-68077?
The vulnerability in CVE-2026-68077 is caused by unbounded disposition range handling that leads to naive range processing.