Impact
A pre‑authentication attacker can send crafted AMQP 0‑10 messages that exploit improper type size/count handling in the broker’s decoder, causing the broker to allocate excessive memory and potentially crash. The vulnerability results in a denial of service for all connections that access the broker, with no impact on confidentiality or integrity.
Affected Systems
Apache Qpid Broker‑J versions up to and including 10.1.0 are affected. Users are advised to upgrade to 10.1.1, which contains the fix.
Risk and Exploitability
The CVSS score is not publicly disclosed, but the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited without authentication by sending malformed AMQP packets, making it suitable for remote denial‑of‑service attacks. Because the issue is triggered prior to authentication, any network‑connected client can initiate an exploit. Until the broker is patched, the risk of availability loss remains high.
OpenCVE Enrichment