CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Authenticated producers can disrupt AMQP 0-10 delivery on Qpid Broker-J through 10.1.0.
Apache Qpid Broker-J through 10.1.0 incompletely handles property-encoding exceptions when converting AMQP 1.0 messages to AMQP 0-10. An authenticated message producer can send properties the target encoder does not handle and disrupt delivery to AMQP 0-10 consumers. The vendor rates the flaw moderate.
- AMQP 1.0-to-0-10 conversion mishandles some property-encoding exceptions.
- Authenticated producers can disrupt delivery to AMQP 0-10 consumers.
- Affects Broker-J through 10.1.0; vendor severity is moderate.
Vulnerabilities mentionedAll →
- CVE-2026-926087.5—Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to…published
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92608 | Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to… Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. NVD description · AI analysis pending |
Posted by Daniil Kirilyuk on Sep 24 Severity: moderate Affected versions: - Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0) through 10.1.0 Description: Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid...
This source does not provide full text. Read it at seclists.org.