CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid Broker-J: through 10.1.0.
Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.1
Event History
Frequently Asked Questions
Who can exploit this issue?
A pre-authentication attacker can exploit the affected AMQP 0-8, 0-9, or 0-9-1 field-table processing. Authentication is not required.
What is the likely impact of exploitation?
Exploitation can trigger a StackOverflowError through unbounded type nesting, potentially causing a denial of service.
Which versions are affected and what version fixes the issue?
Apache Qpid Broker-J versions through 10.1.0 are affected. Upgrading to version 10.1.1 fixes the issue.