Apache

Qpid Broker-j

21 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 25.09.2026 08:17:38
  • Zuletzt bearbeitet 05.10.2026 18:19:20

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1,...

  • EPSS 0.37%
  • Veröffentlicht 25.09.2026 08:17:01
  • Zuletzt bearbeitet 05.10.2026 18:06:34

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1,...

  • EPSS 0.29%
  • Veröffentlicht 25.09.2026 08:11:12
  • Zuletzt bearbeitet 05.10.2026 18:01:53

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrup...

  • EPSS 0.19%
  • Veröffentlicht 25.09.2026 07:59:30
  • Zuletzt bearbeitet 05.10.2026 18:04:01

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fix...

  • EPSS 0.32%
  • Veröffentlicht 25.09.2026 07:44:26
  • Zuletzt bearbeitet 05.10.2026 18:19:28

Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. ...

  • EPSS 0.38%
  • Veröffentlicht 25.09.2026 07:44:10
  • Zuletzt bearbeitet 05.10.2026 18:08:07

Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. This issue affects Apache Qpid...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 05:51:22
  • Zuletzt bearbeitet 06.08.2026 18:39:17

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. ...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 05:43:35
  • Zuletzt bearbeitet 06.08.2026 18:39:28

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1....

  • EPSS 0.17%
  • Veröffentlicht 05.08.2026 05:41:07
  • Zuletzt bearbeitet 06.08.2026 18:34:45

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommend...

  • EPSS 0.17%
  • Veröffentlicht 05.08.2026 05:36:02
  • Zuletzt bearbeitet 06.08.2026 18:34:55

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the i...