ZeroHour

CVE-2026-66276

CVSS 3.1
6.5 medium
EPSS
<1%p36
Published
()
Modified
Description

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

Vendors
apache
Products
qpid proton-j
Weakness
CWE-606
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.