Denial of Service Vulnerability in Apache Qpid Broker-J
CVE-2026-68077
6.5MEDIUM
What is CVE-2026-68077?
An issue has been identified in Apache Qpid Broker-J where an authenticated attacker can send a specially crafted disposition frame containing large or illegal ranges. This action can lead to excessive CPU usage due to ineffective range handling, resulting in denial of service. To mitigate this risk, users should upgrade to version 10.1.0, which addresses the vulnerability and enhances system stability.
Affected Version(s)
Apache Qpid Broker-J 0 <= 10.0.1