Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can send data that exceeds the broker’s incoming session flow control window, which may cause the Qpid Broker‑J server to become unresponsive or crash. The weakness is identified as a Resource Exhaustion flaw (CWE‑770) and can compromise availability for affected services.

Affected Systems

The bug affects Apache Qpid Broker‑J versions up to and including 10.0.1, as released by the Apache Software Foundation.

Risk and Exploitability

The vulnerability requires the user to be authenticated before exploitation can occur; an authenticated attacker can send traffic that exceeds the broker’s session flow‑control window, potentially leading to a denial of service. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the overall risk to a given environment depends on factors such as how exposed the broker is and how many authenticated users are present, but the severity alone does not quantify exploitation likelihood.

Generated by OpenCVE AI on August 5, 2026 at 08:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Apache Qpid Broker‑J 10.1.0 or later to receive the fix.
  • Enforce strict authentication and authorization controls to limit which users can initiate sessions with the broker.
  • Monitor broker logs for anomalous traffic and, if an immediate upgrade is not possible, apply temporary rate limiting or adjust flow‑control settings to reduce the risk of service interruption.

Generated by OpenCVE AI on August 5, 2026 at 08:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Weaknesses CWE-770
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T06:58:28.637Z

Reserved: 2026-07-30T09:07:48.378Z

Link: CVE-2026-68075

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T08:45:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling