Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67592

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

A flaw was found in Apache Qpid ProtonJ2. An authenticated attacker could exploit a vulnerability where the system fails to limit the number of incoming data transfers. This oversight allows the attacker to consume excessive system resources, potentially leading to a denial of service (DoS), which makes the system unavailable to legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Clientsprotonj2Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2511341org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers

EPSS

Процентиль: 39%
0.00478
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
27 дней назад

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

CVSS3: 7.5
nvd
27 дней назад

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

CVSS3: 7.5
github
27 дней назад

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue

EPSS

Процентиль: 39%
0.00478
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-67592