Impact
A vulnerability in Apache Qpid Proton-J allows a pre‑authentication attacker to manipulate type size and count handling, causing the program to allocate excessively large buffers. This can lead to a denial of service by exhausting system resources, impacting availability. The weakness is classified as CWE‑789, an improper input validation problem potentially involving uncontrolled memory allocation.
Affected Systems
The flaw affects all installations of Apache Qpid Proton-J up to and including version 0.34.1. The affected product is Apache Qpid Proton-J, produced by the Apache Software Foundation. Versions released before 0.35.0 may be exposed; only version 0.35.0 and later contain the fix.
Risk and Exploitability
Because the issue is exploitable prior to any user authentication and does not require special privileges, the attack vector is relatively broad. The EPSS score of < 1 % indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying that known exploit code has not yet been observed in the wild. Users should consider the possibility of denial of service attacks from untrusted network traffic. The CVSS score is 7.5, reflecting a high severity that underscores the urgency of addressing the vulnerability.
OpenCVE Enrichment