Description
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability prevents the governance of maximum transfer frames per incoming delivery, allowing an authenticated attacker to deliver an excessive number of transfer frames, leading to elevated resource consumption and a potential denial of service. The impact is a loss of availability due to resource exhaustion, affecting system stability for affected users.

Affected Systems

The affected product is Apache Qpid ProtonJ2 from the Apache Software Foundation. All releases through 1.1.0 are vulnerable, and the issue is fixed in version 1.2.0.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity for this vulnerability. It requires authentication, so only authorized users who can establish connections can exploit the resource exhaustion. The EPSS score is <1%, and the vulnerability is not listed in CISA KEV, suggesting that exploitation would likely require intentional abuse rather than exploitation of a default or publicly exposed interface.

Generated by OpenCVE AI on August 5, 2026 at 17:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid ProtonJ2 to version 1.2.0 or later.
  • If an immediate upgrade is infeasible, restrict authenticated access by limiting users that can establish connections, and monitor for abnormal transfer frame activity indicating abuse.
  • Implement general resource‑limit best practices, such as configuring system kernel limits or container quotas, to mitigate the effect of excessive transfer frames in case a temporary workaround is needed.

Generated by OpenCVE AI on August 5, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache qpid Proton-j
Vendors & Products Apache qpid Proton-j

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 05 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue
Title Apache Qpid ProtonJ2: Unable to govern the maximum number of transfer frames per incoming delivery
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Proton-j Qpid Protonj2
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T15:20:13.011Z

Reserved: 2026-07-29T20:30:23.384Z

Link: CVE-2026-67592

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:20.754Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:38.853

Modified: 2026-08-07T19:44:29.697

Link: CVE-2026-67592

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-05T05:44:18Z

Links: CVE-2026-67592 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:15:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling