Denial of Service Vulnerability in Apache Qpid Broker-J
CVE-2026-68074

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
5 August 2026

What is CVE-2026-68074?

A pre-authentication vulnerability in Apache Qpid Broker-J allows attackers to exploit unbounded symbol value caching. This exploitation can lead to resource exhaustion, ultimately resulting in denial of service. To mitigate this risk, users are urged to upgrade to version 10.1.0, which addresses this issue effectively.

Affected Version(s)

Apache Qpid Broker-J 0 <= 10.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.