https://seclists.org/oss-sec/2026/q3/414: CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation p-authentication
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
maven/org.apache.qpid/qpid-broker-plugins-amqp-1-0-protocol<=10.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-68060?
The severity of CVE-2026-68060 is classified as important.
2
Which versions are affected by CVE-2026-68060?
CVE-2026-68060 affects Apache Qpid Broker-J versions up to 10.0.1.
3
What type of attack does CVE-2026-68060 expose the system to?
CVE-2026-68060 allows a pre-authentication attacker to exploit type size/count handling, potentially leading to a denial of service.
4
How can CVE-2026-68060 be mitigated?
To mitigate CVE-2026-68060, it is recommended to upgrade to a version of Apache Qpid Broker-J that is not affected by this vulnerability.
5
What impacts could result from CVE-2026-68060?
The impacts of CVE-2026-68060 include excessive allocation of resources, which can lead to a denial of service condition.