Description
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.1.0.

Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Published: 2026-09-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A pre‑authentication attacker can send crafted AMQP 0‑10 messages that exploit improper type size/count handling in the broker’s decoder, causing the broker to allocate excessive memory and potentially crash. The vulnerability results in a denial of service for all connections that access the broker, with no impact on confidentiality or integrity.

Affected Systems

Apache Qpid Broker‑J versions up to and including 10.1.0 are affected. Users are advised to upgrade to 10.1.1, which contains the fix.

Risk and Exploitability

The CVSS score is not publicly disclosed, but the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited without authentication by sending malformed AMQP packets, making it suitable for remote denial‑of‑service attacks. Because the issue is triggered prior to authentication, any network‑connected client can initiate an exploit. Until the broker is patched, the risk of availability loss remains high.

Generated by OpenCVE AI on September 25, 2026 at 09:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker‑J to version 10.1.1 or later.
  • Restrict AMQP traffic to trusted IP addresses or apply network‑based filtering until the upgrade is performed.
  • Configure the broker or surrounding network devices to detect oversized AMQP packets, terminate malicious connections, and apply rate‑limiting to mitigate DoS attempts.

Generated by OpenCVE AI on September 25, 2026 at 09:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Fri, 25 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
References

Fri, 25 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Title Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
Weaknesses CWE-770
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-25T13:11:31.985Z

Reserved: 2026-09-16T13:25:51.418Z

Link: CVE-2026-92560

cve-icon Vulnrichment

Updated: 2026-09-25T09:12:50.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T09:17:06.587

Modified: 2026-09-25T14:17:21.993

Link: CVE-2026-92560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T10:45:17Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling