CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
Apache Qpid Broker-J through 10.1.0 has a pre-authentication AMQP 0-8/0-9 decoder DoS, CVE-2026-92550, fixed in 10.1.1.
Apache disclosed CVE-2026-92550 in Qpid Broker-J through 10.1.0, affecting qpid-broker-plugins-amqp-0-8-protocol. A pre-authentication attacker can misuse type size and count handling in the AMQP 0-8, 0-9, and 0-9-1 decoder to cause excessive allocation and potential denial of service. Users are advised to upgrade to 10.1.1. Khaled Suliman is credited, and exploitation is not reported.
- Affects the AMQP 0-8, 0-9, and 0-9-1 decoder through 10.1.0.
- Pre-authentication size and count handling can cause denial of service.
- Fixed in Broker-J 10.1.1; Khaled Suliman is credited.
Vulnerabilities mentionedAll →
- CVE-2026-925507.5—Unauthenticated Memory-Exhaustion DoS in Apache Qpid Broker-J AMQP 0-8/0-9/0-9-1 Decoderpublished · Apache Qpid Broker-J
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92550 | Unauthenticated Memory-Exhaustion DoS in Apache Qpid Broker-J AMQP 0-8/0-9/0-9-1 Decoder Apache Qpid Broker-J through version 10.1.0 contains a denial-of-service vulnerability (CWE-789) in its AMQP 0-8/0-9/0-9-1 protocol decoder. A remote attacker who can reach the broker's AMQP port can send crafted frames whose type size/count fields request an excessively large memory allocation, and this happens before authentication, so no credentials are required. The resulting allocation can exhaust broker memory and crash or hang the service, disrupting message delivery for dependent applications. The issue affects all deployments running Qpid Broker-J version 10.1.0 or earlier, and it is fixed in version 10.1.1. No CVSS score has been assigned yet, and no public proof-of-concept or observed exploitation is known. |
Posted by Daniil Kirilyuk on Sep 24 Severity: important Affected versions: - Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0 Description: A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. Credit: Khaled Suliman...
This source does not provide full text. Read it at seclists.org.