CVE-2026-66277
published 2026-08-05CVE-2026-66277: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.42%
35.4th percentile
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_proton-j | < 0.35.0 | 0.35.0 |
| apache_software_foundation | apache_qpid_proton-j | <= 0.34.1 | — |
| apache_software_foundation | apache_qpid_proton-j | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames
vendor_redhat·2026-08-05·CVSS 6.5
CVE-2026-66277 [MEDIUM] CWE-770 org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames
org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames
A flaw was found in Apache Qpid Proton-J. An authenticated attacker could exploit this by sending an excessive number of transfer frames, leading to uncontrolled resource usage and a potential denial of service (DoS). This vulnerability arises because the system does not properly govern the maximum number of transfer frames per incoming delivery.
Package: amq-broker-bin.zip (Red Hat AMQ Broker 7) - Fix deferred
Package: amq-broker-maven-repository.zip (Red Hat AMQ Broker 7) - Fix deferred
Package: proton-j (Red Hat AMQ Clients) - Fix deferred
Package: proton-j (Red Hat build of Apache Camel 4 for Quarkus 3) - Fix deferred
Package: rhaf-camel-for-springboot-maven-repository.zip (Red Hat
GHSA
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
ghsa_unreviewed·2026-08-05
CVE-2026-66277 [MEDIUM] CWE-770 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid Proton-J: through 0.34.1.
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
No detection rules found.
No public exploits indexed.
2026-08-05
Published