7.5
CVE-2026-67589
- EPSS 0.49%
- Veröffentlicht 05.08.2026 05:28:15
- Zuletzt bearbeitet 07.08.2026 20:39:28
- CVE-Watchlists
- Unerledigt
Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Qpid Protonj2 Version < 1.2.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.398 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-789 Memory Allocation with Excessive Size Value
The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.
https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q
http://www.openwall.com/lists/oss-security/2026/08/04/28