Impact
This vulnerability allows an attacker, before authentication, to trigger unbounded caching of symbol values within Apache Qpid ProtonJ2. The excessive memory consumption can eventually exhaust system resources, causing the affected component to become unresponsive and resulting in a denial‑of‑service condition. The weakness is a classic resource exhaustion problem and is classified as CWE‑770.
Affected Systems
Apache Qpid ProtonJ2 versions up to and including 1.1.0 are affected. Versions 1.2.0 and later contain the fix and are not vulnerable.
Risk and Exploitability
A pre‑authentication attacker who can communicate with a ProtonJ2 endpoint can construct messages that cause the symbol cache to grow without bound. The CVSS score of 7.5 indicates medium‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so no publicly documented exploits are known. An attacker must have network access to an unauthenticated ProtonJ2 service to exploit the flaw.
OpenCVE Enrichment