Impact
Improper handling of compressed data in the shared GZIP decompressor used for AMQP protocol message delivery and HTTP management allows an authenticated message producer to send large or maliciously compressed payloads that are processed without an explicit limit on the uncompressed payload size. This can exhaust broker memory and effectively make the broker unavailable, leading to denial‑of‑service conditions.
Affected Systems
The issue affects all Apache Qpid Broker-J releases up to and including version 10.1.0. Customers running those versions are at risk until they upgrade to the fixed 10.1.1 release or later.
Risk and Exploitability
The vulnerability is classified as a resource‑management flaw (CWE‑409). No EPSS score is presently available and the vulnerability is not listed in the CISA KEV catalog, but the lack of a decompressed‑output limit means that authenticated producers who can manipulate the payload can use this weakness to consume memory. The attacker requires authentication with the broker and can trigger the failure by sending repeatedly compressed messages; no additional network privileges are required beyond normal message‑production rights. The potential impact is local denial of service to the broker service, which may affect all connected clients.
OpenCVE Enrichment