SB2026082555 - Multiple vulnerabilities in Apache Qpid ProtonJ2
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2026-67592)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper resource management in incoming delivery transfer frame handling when processing incoming deliveries. A remote user can send an excessive number of transfer frames to cause a denial of service.
2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-67591)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper enforcement of flow control limits in incoming session flow control handling when processing session flow control updates. A remote user can exceed the session flow control incoming window to cause a denial of service.
3) Uncontrolled Recursion (CVE-ID: CVE-2026-67590)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unbounded type nesting in the type parser when processing nested type data before authentication. A remote attacker can send specially crafted nested type input to cause a denial of service.
4) Input validation error (CVE-ID: CVE-2026-67589)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in type size/count handling when parsing pre-authentication input. A remote attacker can send specially crafted data to cause a denial of service.
5) Resource exhaustion (CVE-ID: CVE-2026-67588)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in symbol value caching when processing untrusted pre-authentication input. A remote attacker can send input that triggers unbounded symbol value caching to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://lists.apache.org/api/email.lua?id=nov3xvfwzsrk6y9o3787jjhbo61djlkd
- https://qpid.apache.org/
- https://lists.apache.org/api/email.lua?id=4bfoj1ny21knxg349w9ocxwk9txjty51
- https://lists.apache.org/api/email.lua?id=nb6hrgd4o9vrt0m91trq60vyjlnq2k7j
- https://lists.apache.org/api/email.lua?id=4d0tdj5kwdvs112p4gm2t6f9d1tod4wk
- https://lists.apache.org/api/email.lua?id=5t916p31hnkvfjk9vt8xs9rpkt1ddjl8