Impact
The vulnerability allows a pre‑authentication attacker to create an arbitrary depth of nested type definitions that can trigger a StackOverflowError in Apache Qpid Broker‑J. The stack overflow can crash the broker process, resulting in a denial of service. This flaw is identified as CWE‑674, indicating uncontrolled recursion or resource exhaustion.
Affected Systems
Apache Qpid Broker‑J from the Apache Software Foundation is affected in all releases through 10.0.1. The vendor recommends upgrading to version 10.1.0, which contains the fix.
Risk and Exploitability
The flaw is exploitable before any authentication is performed, and no EPSS score is available to quantify current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog, but its impact on availability and the ability to crash the broker make it a high‑risk issue. Attackers would need network access to the broker and the ability to send messages that include nested type definitions.
OpenCVE Enrichment