https://seclists.org/oss-sec/2026/q3/418: CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Apache Qpid Broker-J<=10.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-68077?
The severity of CVE-2026-68077 is classified as important.
2
How does CVE-2026-68077 impact Apache Qpid Broker-J?
CVE-2026-68077 allows an authenticated attacker to craft a disposition frame that can cause excessive CPU usage, leading to denial of service.
3
Which versions of Apache Qpid Broker-J are affected by CVE-2026-68077?
CVE-2026-68077 affects all versions of Apache Qpid Broker-J up to and including version 10.0.1.
4
How do I mitigate the risks associated with CVE-2026-68077?
To mitigate the risks of CVE-2026-68077, updating to a patched version of Apache Qpid Broker-J is recommended.
5
What should I do if I suspect an attack exploiting CVE-2026-68077?
If you suspect an attack exploiting CVE-2026-68077, it is important to monitor CPU usage closely and apply security updates immediately.