Description
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly.

This issue affects Apache Qpid Broker-J: through 10.1.0.

Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Published: 2026-09-25
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service to AMQP 0-10 consumers
Action: Immediate Patch
AI Analysis

Impact

The issue stems from improper handling of property-encoding exceptions during conversion from AMQP 1.0 to AMQP 0-10, allowing producers with valid credentials to inject messages containing properties that trigger a failure in the target encoder. As a result, AMQP 0-10 consumers experience delivery disruption, affecting the availability of the messaging service while leaving confidentiality and integrity intact.

Affected Systems

Apache Qpid Broker-J versions up to and including 10.1.0 are affected; users must check whether their installations are running any of these versions.

Risk and Exploitability

The vulnerability is not listed in CISA KEV and its EPSS score is not available, suggesting limited exploit evidence so far. However, because the attack can be carried out by any authenticated message producer, the condition for exploitation is that the attacker can obtain valid producer credentials. An attacker could craft a message with problematic properties to cause conversion errors on consumers, thereby disrupting message delivery. The lack of publicly reported exploits reduces the immediate risk, but the vulnerability can still be abused if the producer can authenticate to the broker.

Generated by OpenCVE AI on September 25, 2026 at 09:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Qpid Broker-J to version 10.1.1 or newer, which removes the fault in property conversion.
  • Disable AMQP 0-10 consumer support or limit it to trusted clients when possible.
  • Monitor broker logs for conversion error messages and investigate any unexpected message drops.

Generated by OpenCVE AI on September 25, 2026 at 09:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 25 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
References

Fri, 25 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache qpid Broker-j
Vendors & Products Apache
Apache qpid Broker-j

Fri, 25 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Title Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Weaknesses CWE-248
References

Subscriptions

Apache Qpid Broker-j
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-25T15:36:03.892Z

Reserved: 2026-09-16T13:57:20.861Z

Link: CVE-2026-92608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-25T08:16:41.083

Modified: 2026-09-25T16:17:29.817

Link: CVE-2026-92608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T09:15:19Z

Weaknesses