SB2026082554 - Multiple vulnerabilities in Apache Qpid Proton Dotnet
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Input validation error (CVE-ID: CVE-2026-67551)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of type size and count values in Apache Qpid Proton Dotnet when parsing protocol data. A remote attacker can send crafted input to cause a denial of service.
The issue can be triggered before authentication.
2) Resource exhaustion (CVE-ID: CVE-2026-67555)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in incoming delivery transfer frame handling when processing an excessive number of transfer frames per incoming delivery. A remote user can send a large number of transfer frames in a delivery to cause a denial of service.
3) Input validation error (CVE-ID: CVE-2026-67554)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in disposition frame range handling when processing crafted disposition frames with large or illegal ranges. A remote user can send a specially crafted disposition frame to cause a denial of service.
4) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-67553)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper flow control in the incoming session flow control window handling in Apache Qpid Proton Dotnet when processing authenticated session flow control operations. A remote user can exceed the incoming session flow control window to cause a denial of service.
5) Uncontrolled Recursion (CVE-ID: CVE-2026-67552)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unbounded type nesting in the type handling logic when parsing nested types. A remote attacker can send specially crafted input with deeply nested types to cause a denial of service.
The issue can be exploited prior to authentication.
6) Resource exhaustion (CVE-ID: CVE-2026-67465)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in symbol value caching when processing pre-authentication input. A remote attacker can send input with unbounded symbol values to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=q2gts7xl974f6ob1wqw6zzj0wrqpztbl
- https://qpid.apache.org/
- https://lists.apache.org/api/email.lua?id=n05cztnq4qsy5yj72s7l55c1gmnzntpj
- https://lists.apache.org/api/email.lua?id=8px9h05dj30xw8mrzs3dylk1sdm1swvy
- https://lists.apache.org/api/email.lua?id=xdrkkrw0wxhczbsj6psj7j4nr425851c
- https://lists.apache.org/api/email.lua?id=5bb1crkmwp744hxbyk5dz6n9vcdxo5oy
- https://lists.apache.org/api/email.lua?id=4o27blqpyhn1z3s9d7sbcwhml5r24fwn