Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-92608— Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10

Quick assessment

Affected
Apache Software Foundation Apache Qpid Broker-J
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Qpid Broker-J 中在将 AMQP 1.0 消息转换为 AMQP 0-10 消息时,对属性编码异常的处理不当。攻击者只需具备消息生产者身份(即已认证),便可构造包含目标编码器无法正确处理的消息属性的消息,从而干扰这些消息向 AMQP 0-10 消费者的投递,导致服务中断。 该漏洞影响 Apache Qpid Broker-J 版本直至 10.1.0。建议用户升级至已修复此问题的 10.1.1 版本。

AI Predicted 5.9 Difficulty: Easy EPSS 0.32% · P23
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92608

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Source: CVE Program / CVE List V5
Vulnerability Description
Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
未捕获的异常
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Qpid Broker-J 0 ~ 10.1.0 -

II. Public POCs for CVE-2026-92608

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92608

请登录查看更多情报信息。

Other References for CVE-2026-92608 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-25 · 6 CVEs total

CVE-2026-92550 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen
CVE-2026-92560 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authen
CVE-2026-92573 Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression
CVE-2026-92564 Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication
CVE-2026-92609 Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication

IV. Related Vulnerabilities

V. Comments for CVE-2026-92608

No comments yet


Leave a comment