CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit.
This issue affects Apache Qpid Broker-J: through 10.1.0.
Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Qpid Broker-Jto a version that resolves this vulnerability.Fixed in 10.1.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated message producer can exploit it. The affected processing paths include AMQP 0-8, 0-9, 0-9-1, and 0-10 message delivery, message conversion, and HTTP management JSON rendering.
What is the impact of successful exploitation?
A producer can cause the broker to process compressed data without a decompressed-output limit, exhausting memory and disrupting broker availability.
Which versions are affected and what version fixes it?
Apache Qpid Broker-J through version 10.1.0 is affected. Version 10.1.1 fixes the issue.