Description
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker can trigger an unbounded echo flow in Apache Qpid Broker‑J, causing the broker to output an excessive amount of data. This unverified, unchecked response leads to high CPU, memory, or network usage, which can ultimately render the broker unavailable to all users. The weakness is classified as CWE‑406, indicating that the system does not properly control or verify output that depends on user input.

Affected Systems

Apache Qpid Broker‑J versions 10.0.1 and earlier are affected. The vendor recommends upgrading to version 10.1.0 to remediate the issue. Only deployments that allow authenticated clients to send echo flow commands are susceptible.

Risk and Exploitability

The EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. However, the flaw requires valid broker credentials. An attacker who gains or possesses legitimate access can reliably trigger resource exhaustion, so the practical threat is significant in environments that expose broker services to authenticated clients. The CVSS score of 6.5 indicates moderate severity.

Generated by OpenCVE AI on August 5, 2026 at 16:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.0
  • Restrict broker authentication to trusted users and enforce strict access controls
  • Monitor broker resources for sudden spikes in CPU or memory and configure alerts for excessive flow responses

Generated by OpenCVE AI on August 5, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Title Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Weaknesses CWE-406
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-08-05T14:58:48.703Z

Reserved: 2026-07-30T09:23:54.592Z

Link: CVE-2026-68080

cve-icon Vulnrichment

Updated: 2026-08-05T06:58:34.554Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T07:16:39.443

Modified: 2026-08-06T18:39:17.120

Link: CVE-2026-68080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T17:00:12Z

Weaknesses
  • CWE-406

    Insufficient Control of Network Message Volume (Network Amplification)