Uncontrolled Recursion in Apache Qpid Proton Dotnet - CVE-2026-67552
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to unbounded type nesting in the type handling logic when parsing nested types. A remote attacker can send specially crafted input with deeply nested types to cause a denial of service.
The issue can be exploited prior to authentication.