Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated attacker to exceed the session flow control incoming window in Apache Qpid ProtonJ2, leading to resource exhaustion and denial of service. It is classified as a Capacity Overflow (CWE-770).

Affected Systems

Systems running Apache Qpid ProtonJ2 up to and including version 1.1.0 are impacted. The product is maintained by the Apache Software Foundation and it is inferred that any Java application embedding ProtonJ2 may be affected.

Risk and Exploitability

Because authentication is required, the likely attack vector involves an authenticated network channel or local access with valid credentials. The CVSS score is 6.5 and the EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Applying the upgrade to 1.2.0 removes the risk.

Generated by OpenCVE AI on August 6, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ProtonJ2 library to version 1.2.0 or later in all affected deployments.
  • Restrict authentication to trusted roles and audit credentials to reduce the attack surface.
  • Enforce network segmentation so that only internal trusted services can communicate with ProtonJ2 endpoints.

Generated by OpenCVE AI on August 6, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache qpid Proton-j
Vendors & Products Apache qpid Proton-j

Thu, 06 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Title Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-j Qpid Protonj2
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T15:16:01.150Z

Reserved: 2026-07-29T20:26:55.665Z

Link: CVE-2026-67591

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:18.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:38.737

Modified: 2026-08-07T19:44:17.873

Link: CVE-2026-67591

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:15:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling