Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker, before authentication, to trigger unbounded caching of symbol values within Apache Qpid ProtonJ2. The excessive memory consumption can eventually exhaust system resources, causing the affected component to become unresponsive and resulting in a denial‑of‑service condition. The weakness is a classic resource exhaustion problem and is classified as CWE‑770.

Affected Systems

Apache Qpid ProtonJ2 versions up to and including 1.1.0 are affected. Versions 1.2.0 and later contain the fix and are not vulnerable.

Risk and Exploitability

A pre‑authentication attacker who can communicate with a ProtonJ2 endpoint can construct messages that cause the symbol cache to grow without bound. The CVSS score of 7.5 indicates medium‑to‑high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so no publicly documented exploits are known. An attacker must have network access to an unauthenticated ProtonJ2 service to exploit the flaw.

Generated by OpenCVE AI on August 5, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Qpid ProtonJ2 version 1.2.0 or later to apply the official fix.
  • Limit the exposure of ProtonJ2 services to trusted networks or enforce firewall rules to restrict unauthenticated access.
  • Monitor memory and CPU usage of ProtonJ2 services for abnormal spikes, and configure process or system limits to contain potential resource exhaustion.

Generated by OpenCVE AI on August 5, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Wed, 05 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton-j
Vendors & Products Apache
Apache qpid Proton-j

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Title Apache Qpid ProtonJ2: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-j Qpid Protonj2
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T13:44:32.387Z

Reserved: 2026-07-29T20:10:04.188Z

Link: CVE-2026-67588

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:12.907Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T06:16:39.450

Modified: 2026-08-07T20:40:16.760

Link: CVE-2026-67588

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-05T05:21:44Z

Links: CVE-2026-67588 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T14:15:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling