Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-66274

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

A flaw was found in Apache Qpid Proton-J. A remote attacker, without needing to authenticate, could exploit a vulnerability related to unbounded type nesting. This could lead to a StackOverflowError, causing the affected system to become unresponsive and resulting in a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7amq-broker-bin.zipAffected
Red Hat AMQ Broker 7amq-broker-maven-repository.zipAffected
Red Hat AMQ Clientsproton-jAffected
Red Hat build of Apache Camel 4 for Quarkus 3proton-jAffected
Red Hat build of Apache Camel for Spring Boot 4rhaf-camel-for-springboot-maven-repository.zipAffected
Red Hat build of Apache Camel for Spring Boot 4rhaf-camel-maven-repository.zipAffected
Red Hat build of Apache Camel for Spring Boot 4rhaf-camel-spring-boot-maven-repository.zipAffected
Red Hat build of Quarkusproton-jAffected
Red Hat JBoss Enterprise Application Platform Expansion Packproton-jAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2511337org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting

EPSS

Процентиль: 11%
0.00211
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
2 дня назад

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

debian
2 дня назад

A pre-authentication attacker could leverage type nesting to cause a S ...

CVSS3: 7.5
github
2 дня назад

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

EPSS

Процентиль: 11%
0.00211
Низкий

7.5 High

CVSS3