Allocation of Resources Without Limits or Throttling in Apache Qpid Proton Dotnet - CVE-2026-67553

 

Allocation of Resources Without Limits or Throttling in Apache Qpid Proton Dotnet - CVE-2026-67553

Published: August 25, 2026


Vulnerability identifier: #VU145173
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-67553
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper flow control in the incoming session flow control window handling in Apache Qpid Proton Dotnet when processing authenticated session flow control operations. A remote user can exceed the incoming session flow control window to cause a denial of service.


Affected software

Apache Qpid Proton Dotnet

How to mitigate CVE-2026-67553

Install security update from vendor's website.

Apache Qpid Proton Dotnet - update to 1.1.0

External References

Related Security Bulletins