Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Apache Qpid Broker-J contains a flaw that allows an attacker to send protocol messages before authentication, causing the broker to unboundedly cache symbol values. This results in rapid consumption of memory or CPU resources, eventually exhausting the broker’s resources and causing a denial of service. The weakness is identified as CWE‑770, reflecting unchecked resource consumption.

Affected Systems

Apache Qpid Broker‑J versions through 10.0.1 are affected. Versions 10.1.0 and later are not impacted.

Risk and Exploitability

The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, indicating a low publicly known exploitation probability. However, the CVSS score of 7.5 denotes a high severity risk to availability. The vulnerability can be triggered before authentication by sending crafted protocol messages, meaning unauthenticated users can initiate resource exhaustion if the broker is exposed to the network.

Generated by OpenCVE AI on August 6, 2026 at 17:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.0, which removes the unbounded caching behavior.
  • Restart the broker service to ensure the new version is loaded and active.
  • Monitor resource usage on the broker to detect abnormal memory or CPU consumption that may indicate exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 17:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-06T13:18:48.748Z

Reserved: 2026-07-30T09:04:07.195Z

Link: CVE-2026-68074

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:26.656Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T06:16:39.877

Modified: 2026-08-07T12:52:35.970

Link: CVE-2026-68074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:15:01Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling