SB2026082554 - Multiple vulnerabilities in Apache Qpid Proton Dotnet



SB2026082554 - Multiple vulnerabilities in Apache Qpid Proton Dotnet

Published: August 25, 2026

Security Bulletin ID SB2026082554
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 6
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 6 vulnerabilities.


1) Input validation error (CVE-ID: CVE-2026-67551)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of type size and count values in Apache Qpid Proton Dotnet when parsing protocol data. A remote attacker can send crafted input to cause a denial of service.

The issue can be triggered before authentication.


2) Resource exhaustion (CVE-ID: CVE-2026-67555)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper resource management in incoming delivery transfer frame handling when processing an excessive number of transfer frames per incoming delivery. A remote user can send a large number of transfer frames in a delivery to cause a denial of service.


3) Input validation error (CVE-ID: CVE-2026-67554)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper input validation in disposition frame range handling when processing crafted disposition frames with large or illegal ranges. A remote user can send a specially crafted disposition frame to cause a denial of service.


4) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-67553)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper flow control in the incoming session flow control window handling in Apache Qpid Proton Dotnet when processing authenticated session flow control operations. A remote user can exceed the incoming session flow control window to cause a denial of service.


5) Uncontrolled Recursion (CVE-ID: CVE-2026-67552)

CWE-ID: CWE-674 - Uncontrolled Recursion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to unbounded type nesting in the type handling logic when parsing nested types. A remote attacker can send specially crafted input with deeply nested types to cause a denial of service.

The issue can be exploited prior to authentication.


6) Resource exhaustion (CVE-ID: CVE-2026-67465)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in symbol value caching when processing pre-authentication input. A remote attacker can send input with unbounded symbol values to cause a denial of service.


Remediation

Install update from vendor's website.