Impact
An authenticated attacker can cause the Proton-J session flow control window to be exceeded, which may result in the process running out of resources and becoming unresponsive, effectively disabling communication for the affected connection. This flaw, categorized as CWE-770, directly threatens availability by allowing an attacker to trigger resource exhaustion on a recipient that has already authenticated.
Affected Systems
The vulnerability affects the Apache Qpid Proton-J library up through version 0.34.1. Users should verify they are running 0.35.0 or later to be protected; any deployment using earlier releases is susceptible.
Risk and Exploitability
No EPSS score is publicly available, and the vulnerability is not listed in CISA’s KEV catalog, but the potential for a denial of service suggests a high impact if exploited. The attack likely requires legitimate authentication to establish a session, after which the attacker can send a volume of data that forces the flow‑control window past its limit. Because the flaw manipulates internal resource accounting, successful exploitation could leave the target process in an unrecoverable state until restarted.
OpenCVE Enrichment