Impact
The flaw arises from unbounded caching of symbol values in Apache Qpid Broker-J, allowing a pre‑authentication attacker to trigger resource exhaustion and cause a denial of service. This weakness does not grant access privileges but can crash the broker by consuming memory or CPU, disrupting any client that relies on the service. The vulnerability is categorized as CWE‑770, reflecting unchecked resource consumption.
Affected Systems
Apache Qpid Broker‑J, versions through 10.0.1 are affected. Users of older releases are not impacted.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low publicly known exploitation activity. However, because the attack can be performed before authentication and merely requires sending protocol messages, the potential impact is high for exposed brokers. No CVSS score is provided, so administrators should treat it as a significant risk for availability.
OpenCVE Enrichment