Impact
The vulnerability allows an attacker to construct deeply nested type structures within AMQP 0-8/0-9/0-9-1 field tables. When the broker processes these structures before any authentication, it can trigger a StackOverflowError that terminates the broker or leaves it in an unstable state, effectively denying service to legitimate clients.
Affected Systems
Apache Qpid Broker-J versions through 10.1.0 are affected. The issue is present in all installations using the default AMQP protocol handling prior to the fix shipped in 10.1.1.
Risk and Exploitability
The exploit requires the attacker to send a specially crafted AMQP message; no authentication is necessary. While there is no EPSS score and the vulnerability is not listed in CISA’s KEV catalog, the impact of causing a broker crash is significant for any environment where Qpid provides critical messaging services. The CVSS score is not provided in the public data, but the nature of the denial-of-service attack and lack of authentication barrier suggest a high severity impact.
OpenCVE Enrichment