https://seclists.org/oss-sec/2026/q3/416: CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to p-authentication source exhaustion
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Apache Qpid Broker-J<=10.0.1, >undefined
Frequently Asked Questions
1
What is the severity of CVE-2026-68074?
The severity of CVE-2026-68074 is classified as important.
2
What versions are affected by CVE-2026-68074?
CVE-2026-68074 affects Apache Qpid Broker-J versions up to and including 10.0.1.
3
How can I fix CVE-2026-68074?
To fix CVE-2026-68074, upgrade to the latest version of Apache Qpid Broker-J that addresses the vulnerability.
4
What is the impact of CVE-2026-68074?
CVE-2026-68074 can lead to resource exhaustion, resulting in denial of service.
5
Can an attacker exploit CVE-2026-68074 before authentication?
Yes, CVE-2026-68074 can be exploited by a pre-authentication attacker.