Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92573— Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering

Quick assessment

Affected
Apache Software Foundation Apache Qpid Broker-J
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在用于 AMQP 0-8/0-9/0-9-1 和 AMQP 0-10 消息传递、消息转换以及 HTTP 管理 JSON 呈现的共享 GZIP 解压器中,对压缩数据的处理不当。经过身份验证的消息生产者可以通过发送无解压缩输出限制的处理请求,耗尽内存并中断消息代理的可用性。 该问题影响 Apache Qpid Broker-J:10.1.0 及之前版本。 建议用户升级到修复了该问题的 10.1.1 版本。

AI Predicted 6.5 Difficulty: Easy EPSS 0.29% · P19
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92573

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
Source: CVE Program / CVE List V5
Vulnerability Description
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Qpid Broker-J 0 ~ 10.1.0 -

II. Public POCs for CVE-2026-92573

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92573

请登录查看更多情报信息。

Other References for CVE-2026-92573 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-25 · 6 CVEs total

CVE-2026-92550 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen
CVE-2026-92560 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen
CVE-2026-92564 Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication
CVE-2026-92608 Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
CVE-2026-92609 Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication

IV. Related Vulnerabilities

V. Comments for CVE-2026-92573

No comments yet


Leave a comment