Impact
The vulnerability allows an authenticated attacker to control the number of transfer frames in an incoming delivery bundle. Because the broker does not limit this value, the attacker can force the server to process an arbitrarily large number of frames, consuming CPU and memory resources and potentially causing a denial of service.
Affected Systems
Apache Qpid Broker-J versions through 10.0.1 are affected. Users of any community or enterprise builds of the broker with those versions should treat the product as vulnerable.
Risk and Exploitability
The flaw requires authentication, so an attacker must first gain valid login credentials to the broker. Once authenticated, the attacker can trigger excessive resource usage by sending deliveries with a very large number of transfer frames. No public exploit has been observed, the EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. The lack of publicly known exploitation reduces immediate risk, but the ability to cause service impact still warrants timely remediation.
OpenCVE Enrichment