Description
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Apache Qpid Proton-J allows a pre‑authentication attacker to manipulate type size and count handling, causing the program to allocate excessively large buffers. This can lead to a denial of service by exhausting system resources, impacting availability. The weakness is classified as CWE‑789, an improper input validation problem potentially involving uncontrolled memory allocation.

Affected Systems

The flaw affects all installations of Apache Qpid Proton-J up to and including version 0.34.1. The affected product is Apache Qpid Proton-J, produced by the Apache Software Foundation. Versions released before 0.35.0 may be exposed; only version 0.35.0 and later contain the fix.

Risk and Exploitability

Because the issue is exploitable prior to any user authentication and does not require special privileges, the attack vector is relatively broad. The EPSS score of < 1 % indicates a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying that known exploit code has not yet been observed in the wild. Users should consider the possibility of denial of service attacks from untrusted network traffic. The CVSS score is 7.5, reflecting a high severity that underscores the urgency of addressing the vulnerability.

Generated by OpenCVE AI on August 6, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Qpid Proton-J version 0.35.0 or later to apply the fix.
  • Configure firewall rules or rate limiting to restrict the volume of incoming traffic to the Proton-J service before authentication.
  • Set up monitoring and alerting for abnormal memory consumption or service unavailability to potential denial of service attempts.

Generated by OpenCVE AI on August 6, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton-j
Vendors & Products Apache
Apache qpid Proton-j

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Title Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication
Weaknesses CWE-789
References

Subscriptions

Apache Qpid Proton-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T13:48:38.834Z

Reserved: 2026-07-24T11:27:24.425Z

Link: CVE-2026-66273

cve-icon Vulnrichment

Updated: 2026-08-05T06:57:50.909Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T06:16:38.593

Modified: 2026-08-07T12:39:01.270

Link: CVE-2026-66273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:30:16Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value