CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.0.1.
Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68080?
CVE-2026-68080 has a risk score of 23, indicating a significant potential for denial of service.
How do I fix CVE-2026-68080?
To address CVE-2026-68080, users should upgrade to Apache Qpid Broker-J version 10.1.0 or later.
What type of vulnerability is CVE-2026-68080?
CVE-2026-68080 is a denial of service vulnerability caused by unbounded echo flow responses in Apache Qpid Broker-J.
Who is affected by CVE-2026-68080?
Any user running Apache Qpid Broker-J version through 10.0.1 is affected by CVE-2026-68080.
How does CVE-2026-68080 enable an attack?
CVE-2026-68080 allows an authenticated attacker to exploit the unregulated response rate, leading to excessive resource consumption.