https://seclists.org/oss-sec/2026/q3/420: CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow sponses can lead to denial of service
Published Aug 4, 2026
·Updated
Affected Software
1 affected component
Apache Qpid Broker-J<=10.0.1
Frequently Asked Questions
1
What is the severity of CVE-2026-68080?
The severity of CVE-2026-68080 is classified as important.
2
What versions of Apache Qpid Broker-J are affected by CVE-2026-68080?
CVE-2026-68080 affects Apache Qpid Broker-J versions up to 10.0.1.
3
How does CVE-2026-68080 allow for denial of service?
CVE-2026-68080 enables an authenticated attacker to exploit unbounded echo flow responses, leading to excessive resource usage and potential denial of service.
4
How can I fix the vulnerability CVE-2026-68080?
To fix CVE-2026-68080, you should update Apache Qpid Broker-J to a patched version that addresses this vulnerability.
5
Is authentication required to exploit CVE-2026-68080?
Yes, an authenticated attacker is required to exploit CVE-2026-68080.