未经身份验证的攻击者可能利用类型大小/计数的处理方式,导致过度分配,从而可能引发拒绝服务(DoS)问题。 此问题影响 Apache Qpid Broker-J 的版本范围为:10.1.0 及更早版本。 建议用户升级至 10.1.1 版本,该版本已修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Qpid Broker-J | 0 ~ 10.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92550 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92573 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression | |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication | |
| CVE-2026-92608 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 | |
| CVE-2026-92609 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication |
No comments yet