Impact
A pre‑authentication attacker can exploit a flaw in the handling of type size/count values in the AMQP 0‑8/0‑9/0‑9‑1 decoder of Apache Qpid Broker‑J. The vulnerability allows the attacker to force the broker to allocate excessively large buffers, which can exhaust memory and bring the broker to an unresponsive state. The weakness falls under CWE‑789, an improper validation of array bounds leading to resource exhaustion. The impact is a loss of availability for services relying on the broker, without compromising confidentiality or integrity.
Affected Systems
Apache Qpid Broker‑J as distributed by the Apache Software Foundation, affected through version 10.1.0. All deployments of these versions are at risk if exposed to AMQP traffic prior to authentication.
Risk and Exploitability
The attack vector is likely to be remote, requiring the attacker to send malformed AMQP packets before authentication is completed. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog, which suggests limited known exploitation in the wild. However, the nature of the vulnerability and the lack of authentication enforcement make it a high‑risk denial‑of‑service candidate. The official advisory recommends upgrading to version 10.1.1, which resolves the allocation issue.
OpenCVE Enrichment