Description
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Apache Qpid Proton-J prevents limiting the number of transfer frames that can be received for a delivery, allowing an authenticated user to send many frames and exhaust server resources, potentially causing a denial of service.

Affected Systems

Affected systems are instances of Apache Qpid Proton‑J version 0.34.1 and earlier. The issue is resolved in version 0.35.0.

Risk and Exploitability

The vulnerability can only be exploited by an attacker who has authenticated access to the Proton‑J server; no exploit evidence is available and the EPSS score is not available. While visibility into the likelihood of exploitation is limited, the impact of exhausting resources could be severe and the CVSS score is 6.5, indicating moderate severity.

Generated by OpenCVE AI on August 5, 2026 at 13:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Proton-J to version 0.35.0 or later.
  • Ensure that only authenticated users can access the Proton‑J service, reducing the attack surface.
  • Monitor server resource usage and restart the service if excessive consumption is detected.

Generated by OpenCVE AI on August 5, 2026 at 13:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 05 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton-j
Vendors & Products Apache
Apache qpid Proton-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Title Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T15:38:51.857Z

Reserved: 2026-07-24T11:49:53.272Z

Link: CVE-2026-66277

cve-icon Vulnrichment

Updated: 2026-08-05T06:57:59.124Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:37.967

Modified: 2026-08-07T13:05:07.420

Link: CVE-2026-66277

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-05T05:42:30Z

Links: CVE-2026-66277 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T13:45:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling