Impact
An authenticated attacker can construct a disposition frame containing large or illegal ranges, which the library processes with naive, unchecked range handling. This leads to exponentially increased CPU consumption and may eventually bring the messaging service to a halt. The flaw is classified as CWE‑606, reflecting improper validation of input lengths.
Affected Systems
Apache Qpid Proton‑J versions 0.34.1 and earlier are vulnerable. Any deployment of this C library that accepts disposition frames from authenticated clients is at risk, particularly when the broker or transport is exposed to networked users who can supply forged frames.
Risk and Exploitability
Exploitation requires prior authentication to the broker, so an attacker would need valid credentials or unprotected network access. No public exploits have been released and the EPSS score is not provided, but the potential for resource exhaustion raises the risk level. Because it is not included in the CISA KEV catalog and no CVSS score is published, the exact severity assessment is unclear; however, the possibility of sustained CPU exhaustion warrants careful monitoring.
OpenCVE Enrichment