Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated attacker to exceed the session flow control incoming window in Apache Qpid ProtonJ2, leading to resource exhaustion and denial of service. It is classified as a Capacity Overflow (CWE-770).

Affected Systems

Systems running Apache Qpid ProtonJ2 up to and including version 1.1.0 are impacted. The product is maintained by the Apache Software Foundation and it is inferred that any Java application embedding ProtonJ2 may be affected.

Risk and Exploitability

Because authentication is required, the likely attack vector involves an authenticated network channel or local access with valid credentials. No CVSS score or EPSS value is available, and the vulnerability is not listed in the CISA KEV catalog. Applying the upgrade to 1.2.0 removes the risk.

Generated by OpenCVE AI on August 5, 2026 at 08:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the ProtonJ2 library to version 1.2.0 or later in all affected deployments.
  • Restrict authentication to trusted roles and audit credentials to reduce the attack surface.
  • Enforce network segmentation so that only internal trusted services can communicate with ProtonJ2 endpoints.

Generated by OpenCVE AI on August 5, 2026 at 08:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Title Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
Weaknesses CWE-770
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:58:18.816Z

Reserved: 2026-07-29T20:26:55.665Z

Link: CVE-2026-67591

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T08:15:12Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling