Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to manipulate the symbol value caching mechanism in Apache Qpid Proton-Dotnet before any authentication occurs. By causing the cache to grow without bounds, an attacker can exhaust memory or other resources, resulting in a denial of service. This flaw does not provide an attacker with confidential or integrity access; its primary consequence is availability disruption.

Affected Systems

Apache Qpid Proton-Dotnet releases up to and including version 1.0.0 are affected. Versions 1.1.0 and later contain the fix.

Risk and Exploitability

The attack can be performed from any external source that can send messages to the Proton‑Dotnet server, and no authentication is required. The description indicates that pre‑authentication resource exhaustion can be triggered, so it is inferred that the exploitability is high. Based on the information provided, there is no mention of real‑world exploitation, and this absence is inferred as the lack of evidence. Since the vulnerability is not listed in CISA KEV, the immediate threat level is considered moderate, but the potential for widespread service outages means administrators should treat it as high priority. The EPSS score is <1%, indicating a very low probability of exploitation at this time. The CVSS score of 7.5 indicates high severity.

Generated by OpenCVE AI on August 6, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Proton‑Dotnet to version 1.1.0 or later, which patches the caching flaw.
  • If an upgrade is not immediately possible, limit inbound connections or throttle message throughput to reduce cache growth.
  • Monitor memory and cache metrics and set alerts for abnormal spikes to detect ongoing exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton Dotnet
Vendors & Products Apache
Apache qpid Proton Dotnet

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Title Apache Qpid Proton Dotnet: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-dotnet Qpid Proton Dotnet
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T13:26:49.211Z

Reserved: 2026-07-29T18:22:09.508Z

Link: CVE-2026-67465

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:01.071Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T06:16:39.160

Modified: 2026-08-07T12:51:15.670

Link: CVE-2026-67465

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T16:45:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling