Description
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an authenticated attacker to control the number of transfer frames in an incoming delivery bundle. Because the broker does not limit this value, the attacker can force the server to process an arbitrarily large number of frames, consuming CPU and memory resources and potentially causing a denial of service.

Affected Systems

Apache Qpid Broker-J versions through 10.0.1 are affected. Users of any community or enterprise builds of the broker with those versions should treat the product as vulnerable.

Risk and Exploitability

The flaw requires authentication, so an attacker must first gain valid login credentials to the broker. Once authenticated, the attacker can trigger excessive resource usage by sending deliveries with a very large number of transfer frames. No public exploit has been observed, the EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. The lack of publicly known exploitation reduces immediate risk, but the ability to cause service impact still warrants timely remediation.

Generated by OpenCVE AI on August 5, 2026 at 17:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the 10.1.0 patch or later upgrade immediately to address the frame‑count limit flaw.
  • Limit broker exposure by allowing access only from trusted networks or requiring strong authentication for all clients and disabling anonymous access.
  • Monitor broker metrics for abnormal transfer‑frame rates and enforce resource caps in broker configuration to mitigate potential abuse when a patch cannot be applied promptly.

Generated by OpenCVE AI on August 5, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T15:29:55.243Z

Reserved: 2026-07-30T09:17:55.984Z

Link: CVE-2026-68078

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:32.558Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:39.327

Modified: 2026-08-06T18:39:28.313

Link: CVE-2026-68078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:00:10Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling