Description
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A pre‑authentication attacker can send deeply nested data types to Apache Qpid ProtonJ2, causing the application to throw a StackOverflowError. This error can crash the process and expose the service to interruptions. The weakness is identified as CWE‑674, which signifies unbounded recursion leading to stack exhaustion. The direct result is a denial of service that may affect availability of the messaging broker. The impact does not include compromise of data confidentiality or integrity, but it can lead to service outages or forced restarts.

Affected Systems

The vulnerability affects the Apache Qpid ProtonJ2 messaging library as distributed by Apache Software Foundation. All versions through 1.1.0 are susceptible. The fix is included in ProtonJ2 1.2.0 and later releases, which should be deployed by affected users.

Risk and Exploitability

The attack vector is pre‑authentication, so an attacker can trigger the exploit by just connecting to the service and sending specially crafted nested types. No public exploit code is available; the EPSS score is not reported, and the issue is not listed in the CISA KEV catalog. Because a stack overflow will crash the broker, the risk of denial of service is high for systems that rely on continuous availability. The lack of an existing mitigation outside of upgrading the library suggests that the best protection is to move to the fixed version promptly.

Generated by OpenCVE AI on August 5, 2026 at 07:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ProtonJ2 to version 1.2.0 or newer to eliminate the vulnerability.
  • Restrict connections to trusted clients and validate incoming messages to reduce the chance of malformed type nesting reaching the broker.
  • Monitor the broker for stack overflow errors and sudden spikes in resource usage, and plan for rapid failover or restart procedures in the event of an attack.

Generated by OpenCVE AI on August 5, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Proton-j
Vendors & Products Apache
Apache qpid Proton-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Title Apache Qpid ProtonJ2: Unbounded type nesting can lead to pre-authentication stackoverflow
Weaknesses CWE-674
References

Subscriptions

Apache Qpid Proton-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:58:16.871Z

Reserved: 2026-07-29T20:22:34.097Z

Link: CVE-2026-67590

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:30:11Z

Weaknesses