Uncontrolled Recursion in Apache Qpid Proton-J - CVE-2026-66274
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in type nesting processing in Apache Qpid Proton-J when parsing nested AMQP types. A remote attacker can send specially crafted nested type data to cause a denial of service.
The issue can be triggered before authentication.