7.5
CVE-2026-67551
- EPSS 0.49%
- Veröffentlicht 05.08.2026 05:27:24
- Zuletzt bearbeitet 07.08.2026 20:43:29
- CVE-Watchlists
- Unerledigt
Apache Qpid Proton Dotnet: Type size/count handling can lead to excessive allocation pre-authentication
pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Qpid Proton-dotnet Version < 1.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.398 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro
http://www.openwall.com/lists/oss-security/2026/08/04/22