Description
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a pre‑authentication attacker to create an arbitrary depth of nested type definitions that can trigger a StackOverflowError in Apache Qpid Broker‑J. The stack overflow can crash the broker process, resulting in a denial of service. This flaw is identified as CWE‑674, indicating uncontrolled recursion or resource exhaustion.

Affected Systems

Apache Qpid Broker‑J from the Apache Software Foundation is affected in all releases through 10.0.1. The vendor recommends upgrading to version 10.1.0, which contains the fix.

Risk and Exploitability

The flaw is exploitable before any authentication is performed, and no EPSS score is available to quantify current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but its impact on availability and the ability to crash the broker make it a high‑risk issue. Attackers would need network access to the broker and the ability to send messages that include nested type definitions.

Generated by OpenCVE AI on August 5, 2026 at 08:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.0 or later
  • Restrict network access to the broker by configuring firewall rules that allow only trusted IPs to connect
  • Apply OS or container resource limits (e.g., stack size) to mitigate stack overflow effects

Generated by OpenCVE AI on August 5, 2026 at 08:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Weaknesses CWE-674
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:58:24.614Z

Reserved: 2026-07-30T08:58:06.373Z

Link: CVE-2026-68073

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T09:00:05Z

Weaknesses