CVE-2026-66257
published 2026-08-05CVE-2026-66257: A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.43%
35.8th percentile
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_proton-j | < 0.35.0 | 0.35.0 |
| apache | qpid_proton-j | — | — |
| apache_software_foundation | apache_qpid_proton-j | <= 0.34.1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
ghsa_unreviewed·2026-08-05
CVE-2026-66257 CWE-770 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Red Hat
qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
vendor_redhat·2026-08-05·CVSS 7.5
CVE-2026-66257 [HIGH] CWE-770 qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
A flaw was found in Apache Qpid Proton-J. A remote attacker, without needing to authenticate, could exploit an issue with unbounded symbol value caching. This could lead to resource exhaustion, where the system runs out of available resources, ultimately causing a denial of service (DoS). A denial of service attack makes the affected system unavailable to legitimate users.
Package: proton-j (Red Hat AMQ Broker 7) - Affected
Package: pr
No detection rules found.
No public exploits indexed.
2026-08-05
Published