https://seclists.org/oss-sec/2026/q3/415: CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to p-authentication stack overflow
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Apache Qpid Broker-J<=10.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-68073?
The severity of CVE-2026-68073 is classified as important.
2
Which versions of Apache Qpid Broker-J are affected by CVE-2026-68073?
CVE-2026-68073 affects Apache Qpid Broker-J versions through 10.0.1.
3
What is the potential impact of CVE-2026-68073?
CVE-2026-68073 could allow a pre-authentication attacker to exploit type nesting to cause a StackOverflowError, potentially leading to denial of service.
4
How do I fix CVE-2026-68073?
To fix CVE-2026-68073, upgrade to a version of Apache Qpid Broker-J that is newer than 10.0.1.
5
Can a remote attacker exploit CVE-2026-68073?
Yes, a pre-authentication remote attacker can exploit CVE-2026-68073.