CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.1.0.
Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.1
Event History
Frequently Asked Questions
Which broker versions need to be remediated?
Apache Qpid Broker-J versions through 10.1.0 are affected. Upgrade to version 10.1.1, which fixes the issue.
Does an attacker need to authenticate before exploiting this issue?
No. The issue can be triggered by a pre-authentication attacker while the broker processes AMQP 0-8, 0-9, or 0-9-1 protocol data.
What is the likely security impact?
Malformed type size or count handling can cause excessive memory allocation, potentially resulting in denial of service.