Impact
An authenticated attacker can trigger an unbounded echo flow in Apache Qpid Broker‑J, causing the broker to output an excessive amount of data. This unverified, unchecked response leads to high CPU, memory, or network usage, which can ultimately render the broker unavailable to all users. The weakness is classified as CWE‑406, indicating that the system does not properly control or verify output that depends on user input.
Affected Systems
Apache Qpid Broker‑J versions 10.0.1 and earlier are affected. The vendor recommends upgrading to version 10.1.0 to remediate the issue. Only deployments that allow authenticated clients to send echo flow commands are susceptible.
Risk and Exploitability
The EPSS score is < 1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been observed. However, the flaw requires valid broker credentials. An attacker who gains or possesses legitimate access can reliably trigger resource exhaustion, so the practical threat is significant in environments that expose broker services to authenticated clients. The CVSS score of 6.5 indicates moderate severity.
OpenCVE Enrichment