Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid Proton-Dotnet: through 1.0.0.

Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can exceed the session flow control incoming window in Apache Qpid Proton‑Dotnet, potentially leading to a denial of service condition. The flaw is a classic resource exhaustion weakness (CWE‑770). If exploited, the attacker can cause the server to become unresponsive or to consume excessive resources, affecting availability for legitimate users.

Affected Systems

The vulnerability is present in Apache Qpid Proton‑Dotnet version 1.0.0 and all earlier releases. The product is developed by the Apache Software Foundation.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is less than 1%, indicating a low probability of exploitation. The flaw requires authentication, limiting impact to systems where credentials are compromised or misconfigured. There is no evidence of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Even with a low EPSS score, remediation remains necessary, as the impact on availability can be severe for exposed configurations.

Generated by OpenCVE AI on August 6, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Proton‑Dotnet to version 1.1.0 or later, which addresses the session flow control window issue.
  • Restrict external exposure of services using Qpid Proton‑Dotnet, ensuring authentication is only possible from trusted sources.
  • Implement monitoring of session flow control window usage on the server and configure alerts for values approaching the maximum threshold to detect potential abuse early.

Generated by OpenCVE AI on August 6, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache qpid Proton Dotnet
Vendors & Products Apache qpid Proton Dotnet

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Title Apache Qpid Proton Dotnet: Incoming session flow control window can be exceeded
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-dotnet Qpid Proton Dotnet
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T15:19:37.702Z

Reserved: 2026-07-29T19:01:21.332Z

Link: CVE-2026-67553

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:07.010Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:38.223

Modified: 2026-08-07T13:06:22.460

Link: CVE-2026-67553

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:28:29Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling