Impact
A pre‑authentication attacker can cause a StackOverflowError by exploiting unbounded type nesting in Apache Qpid Proton‑Dotnet, potentially leading to denial of service. This overflow is a classic example of uncontrolled recursion, categorized as CWE‑674.
Affected Systems
Apache Qpid Proton‑Dotnet versions through 1.0.0 are affected. Any deployment of these releases is susceptible until updated to 1.1.0 or later.
Risk and Exploitability
The vulnerability lacks a publicly available CVSS score and EPSS data, and it is not listed in the CISA KEV catalog, indicating that exploitation evidence is currently limited. Attackers would need to attach to the Proton‑Dotnet service before authentication and send or receive messages with deeply nested type structures to trigger the stack overflow. Because the fault occurs before authentication, the primary impact is a denial‑of‑service rather than privilege escalation or data loss.
OpenCVE Enrichment