Impact
An attacker can exploit a flaw in type size and count handling in Apache Qpid Broker-J to trigger out‑of‑band memory allocation. The vulnerability, mapped to CWE-770, results in the broker allocating excessively large data structures before authentication, which can exhaust system resources and cause the broker to become unavailable. The impact is a denial of service against the messaging service and the host it runs on.
Affected Systems
Affected are installations of Apache Qpid Broker-J up through version 10.0.1. Any instance of the broker configured with Qpid 10.0.1 or older is vulnerable. The vendor recommends updating to version 10.1.0 or later where the allocation logic has been corrected.
Risk and Exploitability
Because the flaw can be triggered before authentication, an unauthenticated remote attacker may be able to induce a denial of service by sending crafted traffic to the broker. The CVSS score of 7.5 indicates a moderate to high severity, and the EPSS score of less than 1% suggests that immediate exploitation is currently unlikely but should not be dismissed. The vulnerability is not listed in CISA KEV, yet the lack of authentication requirement combined with the potential for full service disruption means the risk to availability is high. Attackers would typically use the broker’s exposed network ports to send malicious messages or requests that exploit the size/count handling flaw.
OpenCVE Enrichment