Impact
The vulnerability is an unbounded symbol value caching flaw that can be triggered by a pre‑authentication attacker. By sending an excessive number of unique symbols before authentication, the attacker can cause the server to allocate unbounded amounts of memory or other resources, leading to a denial of service. This weakness falls under CWE‑770, which concerns uncontrolled resource consumption.
Affected Systems
Apache Qpid Proton‑J, version 0.34.1 and earlier. Users should verify that they are running a version older than 0.35.0, the first release that contains the fix.
Risk and Exploitability
The flaw can be exploited remotely without authentication, allowing an attacker to exhaust server resources and disrupt availability. The CVSS score of 7.5 indicates a high severity, and the EPSS score of <1% suggests a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to establish a connection to the Proton‑J server and transmit large volumes of symbols before authenticating.
OpenCVE Enrichment