Description
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from unbounded caching of symbol values in Apache Qpid Broker-J, allowing a pre‑authentication attacker to trigger resource exhaustion and cause a denial of service. This weakness does not grant access privileges but can crash the broker by consuming memory or CPU, disrupting any client that relies on the service. The vulnerability is categorized as CWE‑770, reflecting unchecked resource consumption.

Affected Systems

Apache Qpid Broker‑J, versions through 10.0.1 are affected. Users of older releases are not impacted.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low publicly known exploitation activity. However, because the attack can be performed before authentication and merely requires sending protocol messages, the potential impact is high for exposed brokers. No CVSS score is provided, so administrators should treat it as a significant risk for availability.

Generated by OpenCVE AI on August 5, 2026 at 06:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.0, which removes the unbounded caching behavior.
  • If an immediate upgrade is not possible, disable or limit the symbol cache configuration to prevent unlimited growth during protocol negotiation.
  • Monitor broker resource usage and enforce rate limiting to detect and mitigate abnormal memory or CPU consumption early.

Generated by OpenCVE AI on August 5, 2026 at 06:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T05:19:55.467Z

Reserved: 2026-07-30T09:04:07.195Z

Link: CVE-2026-68074

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T06:30:03Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling