CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.1.0.
Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.1
Event History
Frequently Asked Questions
Does an attacker need to authenticate to exploit this issue?
No. The issue can be triggered by a pre-authentication attacker through the AMQP 0-10 decoder.
Which deployments are affected?
Apache Qpid Broker-J versions through 10.1.0 are affected. The provided information does not identify configuration-specific prerequisites.
What is the impact of successful exploitation?
An attacker can cause excessive memory allocation through type size/count handling, potentially resulting in denial of service.
What is the recommended remediation?
Upgrade Apache Qpid Broker-J to version 10.1.1, which fixes the issue.