Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache Qpid Broker-J — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Apache Qpid Broker-J, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Vulnerabilities and Exposures (CVEs) associated with Apache Qpid Broker-J, a messaging broker developed by the Apache Software Foundation. It serves as a centralized resource for understanding the security posture and historical vulnerability landscape of this specific Java-based message broker component. The collection covers a comprehensive range of security weaknesses affecting Apache Qpid Broker-J, including but not limited to remote code execution, denial of service, information disclosure, and privilege escalation flaws. The data spans from the initial releases of the product through to the most recent updates, ensuring that researchers and security practitioners have access to both legacy issues and newly identified threats. This time range allows for a longitudinal analysis of the product's security evolution and the effectiveness of patch management strategies over time. Visitors to this page can track vendor-specific advisories issued by the Apache Security Team to monitor how quickly critical flaws are addressed. The aggregated data facilitates a deeper understanding of common weakness classes within the broker’s architecture, helping developers identify potential attack surfaces in their deployments. Furthermore, users can look up the complete vulnerability history for Apache Qpid Broker-J, comparing the frequency and severity of past incidents against industry benchmarks. This context is essential for risk assessment, compliance reporting, and securing messaging infrastructure against evolving cyber threats.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-92550 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder CWE-789 - - 2026-09-25
CVE-2026-92560 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder CWE-770 - - 2026-09-25
CVE-2026-92573 Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering CWE-409 - - 2026-09-25
CVE-2026-92564 Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing CWE-674 - - 2026-09-25
CVE-2026-92608 Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 CWE-248 - - 2026-09-25
CVE-2026-92609 Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication CWE-384 - - 2026-09-25
CVE-2026-68080 Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service CWE-406 - - 2026-08-05
CVE-2026-68078 Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery CWE-770 - - 2026-08-05
CVE-2026-68077 Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service CWE-606 - - 2026-08-05
CVE-2026-68075 Apache Qpid Broker-J: Incoming session flow control window can be exceeded CWE-770 - - 2026-08-05
CVE-2026-68073 Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow CWE-674 - - 2026-08-05
CVE-2026-68060 Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication CWE-770 - - 2026-08-05
CVE-2026-68074 Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion CWE-770 - - 2026-08-05
CVE-2019-0200 Apache Qpid 输入验证错误漏洞 7.5 - 2019-03-06
CVE-2018-8030 Apache Qpid Broker-J 安全漏洞 7.5 - 2018-06-19
CVE-2018-1298 Apache Qpid 安全漏洞 5.9 - 2018-02-09
CVE-2017-15702 Apache Qpid Broker-J 安全漏洞 9.8 - 2017-12-01
CVE-2017-15701 Apache Qpid Broker-J 安全漏洞 7.5 - 2017-12-01
CVE-2016-8741 Apache Qpid Broker for Java 安全漏洞 7.5 - 2017-05-15

All 19 known CVE vulnerabilities affecting Apache Qpid Broker-J with full Chinese analysis, references, and POCs where available.