CVE-2026-67590
published 2026-08-05CVE-2026-67590: A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.49%
40.8th percentile
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_protonj2 | < 1.2.0 | 1.2.0 |
| apache | qpid_protonj2 | — | — |
| apache_software_foundation | apache_qpid_protonj2 | <= 1.1.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Qpid ProtonJ2 up to 1.1.0 Type Nesting recursion
vuldb·2026-08-09·CVSS 7.5
CVE-2026-67590 [HIGH] Apache Qpid ProtonJ2 up to 1.1.0 Type Nesting recursion
A vulnerability was found in Apache Qpid ProtonJ2 up to 1.1.0. It has been declared as critical. This affects an unknown function of the component Type Nesting Handler. Such manipulation leads to uncontrolled recursion.
This vulnerability is uniquely identified as CVE-2026-67590. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
ghsa_unreviewed·2026-08-05
CVE-2026-67590 CWE-674 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Red Hat
qpid-protonj2: Apache Qpid ProtonJ2: Denial of Service via unbounded type nesting
vendor_redhat·2026-08-05·CVSS 7.5
CVE-2026-67590 [HIGH] CWE-770 qpid-protonj2: Apache Qpid ProtonJ2: Denial of Service via unbounded type nesting
qpid-protonj2: Apache Qpid ProtonJ2: Denial of Service via unbounded type nesting
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
A flaw was found in Apache Qpid ProtonJ2. A remote attacker, without needing to authenticate, could exploit a vulnerability related to unbounded type nesting. This could lead to a StackOverflowError, causing the application to become unresponsive and resulting in a denial of service.
Package: protonj2 (Red Hat AMQ Clients) - Affected
No detection rules found.
No public exploits indexed.
2026-08-05
Published