Description
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an uncontrolled recursion flaw that allows a pre‑authentication attacker to create an arbitrary depth of nested type definitions, leading to a StackOverflowError that can crash the Apache Qpid Broker‑J process. This loss of process availability aligns with the CWE‑674 classification for uncontrolled recursion or resource exhaustion. The immediate consequence is a denial of service that impacts the broker's ability to accept or process client connections.

Affected Systems

Apache Qpid Broker‑J from the Apache Software Foundation is affected in all releases up to and including version 10.0.1. The vendor recommends upgrading to version 10.1.0 to receive the fix.

Risk and Exploitability

Based on the description, it is inferred that a remote attacker who can send crafted messages to the broker before authentication could trigger the flaw; the CVSS score of 7.5 indicates high severity, and the EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The lack of authentication needed for exploitation and the potential to crash the broker process mean that any network access to the broker that permits message submission poses a significant risk.

Generated by OpenCVE AI on August 6, 2026 at 23:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.0 or later
  • Restrict network access to the broker by configuring firewall rules that allow only trusted IPs to connect
  • Apply OS or container resource limits (e.g., stack size) to mitigate stack overflow effects

Generated by OpenCVE AI on August 6, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Weaknesses CWE-674
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T15:37:34.545Z

Reserved: 2026-07-30T08:58:06.373Z

Link: CVE-2026-68073

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:24.614Z

cve-icon NVD

Status : Modified

Published: 2026-08-05T07:16:38.973

Modified: 2026-08-06T22:18:24.533

Link: CVE-2026-68073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T23:30:05Z

Weaknesses