https://seclists.org/oss-sec/2026/q3/417: CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Published Aug 4, 2026
·Updated
Affected Software
2 affected components
Apache Qpid Broker-J<=10.0.1
maven/org.apache.qpid/qpid-broker-plugins-amqp-1-0-protocol<=10.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-68075?
The severity of CVE-2026-68075 is classified as important.
2
What versions are affected by CVE-2026-68075?
CVE-2026-68075 affects Apache Qpid Broker-J versions through 10.0.1.
3
How does CVE-2026-68075 affect Apache Qpid Broker-J?
CVE-2026-68075 allows an authenticated attacker to exceed the session flow control incoming window potentially leading to denial of service.
4
What could be a potential impact of CVE-2026-68075?
The potential impact of CVE-2026-68075 is denial of service due to the exceeded session flow control window.
5
How do I fix CVE-2026-68075?
To fix CVE-2026-68075, upgrade to a secure version of Apache Qpid Broker-J that addresses this vulnerability.