在用于 AMQP 0-8/0-9/0-9-1 和 AMQP 0-10 消息传递、消息转换以及 HTTP 管理 JSON 呈现的共享 GZIP 解压器中,对压缩数据的处理不当。经过身份验证的消息生产者可以通过发送无解压缩输出限制的处理请求,耗尽内存并中断消息代理的可用性。 该问题影响 Apache Qpid Broker-J:10.1.0 及之前版本。 建议用户升级到修复了该问题的 10.1.1 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Qpid Broker-J | 0 ~ 10.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92550 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92560 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication | |
| CVE-2026-92608 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 | |
| CVE-2026-92609 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication |
No comments yet