在身份验证之前,攻击者可能利用类型大小/计数处理缺陷,导致过度分配,从而引发潜在的服务拒绝攻击(Denial of Service, DoS)。 此问题影响 Apache Qpid Broker-J 10.1.0 及更早版本。 建议用户升级至版本 10.1.1,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Qpid Broker-J | 0 ~ 10.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92560 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92573 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression | |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication | |
| CVE-2026-92608 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 | |
| CVE-2026-92609 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication |
No comments yet