Improper Handling of Compressed Data in Apache Qpid Broker-J
CVE-2026-92573

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 September 2026

What is CVE-2026-92573?

The vulnerability arises from inadequate handling of compressed messages in the GZIP decompressor utilized by Apache Qpid Broker-J for message delivery and conversion. This flaw allows authenticated message producers to overload the broker’s memory capacity, potentially leading to system instability and disruptions. It is essential for users to upgrade from version 10.1.0 to 10.1.1 to mitigate this issue effectively.

Affected Version(s)

Apache Qpid Broker-J 0 <= 10.1.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Suliman of AISLE Research
n0mi1k
.