Impact
The vulnerability arises from unbounded type nesting that can trigger a StackOverflowError during pre‑authentication. This flaw allows an attacker to construct deeply nested messages, causing the Proton‑J component to crash before authentication completes. The resulting denial of service can prevent legitimate clients from connecting to the messaging service.
Affected Systems
Affected products include Apache Qpid Proton‑J up to and including version 0.34.1. All installations running these versions are susceptible until they are upgraded to 0.35.0, which implements a fix preventing stack overflows caused by nested types.
Risk and Exploitability
Because the flaw is exploitable before authentication, an attacker does not need credentials, only the ability to send messages to the Proton‑J server. The attack requires sending a specially crafted payload with excessive type nesting; no publicly known exploits exist, and the vulnerability is not listed in the CISA KEV catalog. The lack of an EPSS score suggests low current exploitation activity, yet the CVSS rating (not provided) would likely classify the risk as high due to potential service disruption. Immediate patching is advised to mitigate the possibility of a denial‑of‑service incident.
OpenCVE Enrichment