Apache Qpid Broker-J 中在将 AMQP 1.0 消息转换为 AMQP 0-10 消息时,对属性编码异常的处理不当。攻击者只需具备消息生产者身份(即已认证),便可构造包含目标编码器无法正确处理的消息属性的消息,从而干扰这些消息向 AMQP 0-10 消费者的投递,导致服务中断。 该漏洞影响 Apache Qpid Broker-J 版本直至 10.1.0。建议用户升级至已修复此问题的 10.1.1 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Qpid Broker-J | 0 ~ 10.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92550 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92560 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen | |
| CVE-2026-92573 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression | |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication | |
| CVE-2026-92609 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication |
No comments yet