Allocation of Resources Without Limits or Throttling in Apache Qpid Proton Dotnet - CVE-2026-67553
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper flow control in the incoming session flow control window handling in Apache Qpid Proton Dotnet when processing authenticated session flow control operations. A remote user can exceed the incoming session flow control window to cause a denial of service.