Resource exhaustion in Apache Qpid Proton-J - CVE-2026-66257
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in symbol value caching when processing AMQP data. A remote attacker can send input that triggers unbounded symbol value caching to cause a denial of service.
The issue can be exploited prior to authentication.