Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can exceed the session flow control incoming window in Apache Qpid Proton‑Dotnet, potentially leading to a denial of service condition. The flaw is a classic resource exhaustion weakness (CWE‑770). If exploited, the attacker can cause the server to become unresponsive or to consume excessive resources, affecting availability for legitimate users.

Affected Systems

The vulnerability is present in Apache Qpid Proton‑Dotnet version 1.0.0 and all earlier releases. The product is developed by the Apache Software Foundation.

Risk and Exploitability

The CAPEC or CVSS metrics are not publicly disclosed; however, the flaw requires authentication, limiting impact to systems where credentials are compromised or misconfigured. There is no evidence of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The lack of an exploitation probability score does not diminish the need for remediation, as the impact on availability can be severe for exposed configurations.

Generated by OpenCVE AI on August 5, 2026 at 08:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Proton‑Dotnet to version 1.1.0 or later, which addresses the session flow control window issue.
  • Restrict external exposure of services using Qpid Proton‑Dotnet, ensuring authentication is only possible from trusted sources.
  • Implement monitoring of session flow control window usage on the server and configure alerts for values approaching the maximum threshold to detect potential abuse early.

Generated by OpenCVE AI on August 5, 2026 at 08:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Title Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Weaknesses CWE-770
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:58:07.010Z

Reserved: 2026-07-29T19:01:21.332Z

Link: CVE-2026-67553

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T08:15:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling