Impact
A pre‑authentication attacker can cause a StackOverflowError by exploiting unbounded type nesting in Apache Qpid Proton‑Dotnet, potentially leading to denial of service. This overflow is a classic example of uncontrolled recursion, categorized as CWE‑674.
Affected Systems
Apache Qpid Proton‑Dotnet versions through 1.0.0 are affected. Any deployment of these releases is susceptible until updated to 1.1.0 or later.
Risk and Exploitability
The CVSS score of 7.5 and a low EPSS score of < 1% indicate a high severity vulnerability with a low predicted exploitation probability. It is not listed in the CISA KEV catalog, which suggests no public exploitation to date. Attackers would need to attach to the Proton‑Dotnet service before authentication and send or receive messages with deeply nested type structures to trigger the stack overflow. Because the fault occurs before authentication, the primary impact is a denial‑of‑service rather than privilege escalation or data loss.
OpenCVE Enrichment