Impact
An authenticated attacker can exceed the session flow control incoming window in Apache Qpid Proton‑Dotnet, potentially leading to a denial of service condition. The flaw is a classic resource exhaustion weakness (CWE‑770). If exploited, the attacker can cause the server to become unresponsive or to consume excessive resources, affecting availability for legitimate users.
Affected Systems
The vulnerability is present in Apache Qpid Proton‑Dotnet version 1.0.0 and all earlier releases. The product is developed by the Apache Software Foundation.
Risk and Exploitability
The CAPEC or CVSS metrics are not publicly disclosed; however, the flaw requires authentication, limiting impact to systems where credentials are compromised or misconfigured. There is no evidence of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The lack of an exploitation probability score does not diminish the need for remediation, as the impact on availability can be severe for exposed configurations.
OpenCVE Enrichment