Description
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.

This issue affects Apache Qpid Proton-Dotnet through 1.0.0.

Users are recommended to upgrade to version 1.1.0, which fixes the issue
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A pre‑authentication attacker can cause a StackOverflowError by exploiting unbounded type nesting in Apache Qpid Proton‑Dotnet, potentially leading to denial of service. This overflow is a classic example of uncontrolled recursion, categorized as CWE‑674.

Affected Systems

Apache Qpid Proton‑Dotnet versions through 1.0.0 are affected. Any deployment of these releases is susceptible until updated to 1.1.0 or later.

Risk and Exploitability

The CVSS score of 7.5 and a low EPSS score of < 1% indicate a high severity vulnerability with a low predicted exploitation probability. It is not listed in the CISA KEV catalog, which suggests no public exploitation to date. Attackers would need to attach to the Proton‑Dotnet service before authentication and send or receive messages with deeply nested type structures to trigger the stack overflow. Because the fault occurs before authentication, the primary impact is a denial‑of‑service rather than privilege escalation or data loss.

Generated by OpenCVE AI on August 12, 2026 at 00:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Proton‑Dotnet to version 1.1.0 or later
  • Configure the service to limit or reject message type nesting depth if configuration allows
  • Monitor application logs and resource usage for signs of stack exhaustion to detect accidental or malicious triggers

Generated by OpenCVE AI on August 12, 2026 at 00:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton Dotnet
Vendors & Products Apache
Apache qpid Proton Dotnet

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue
Title Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow
Weaknesses CWE-674
References

Subscriptions

Apache Qpid Proton-dotnet Qpid Proton Dotnet
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T15:37:28.470Z

Reserved: 2026-07-29T18:54:36.897Z

Link: CVE-2026-67552

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:38.103

Modified: 2026-08-07T13:05:53.187

Link: CVE-2026-67552

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:15:12Z

Weaknesses