CVE-2026-67592
published 2026-08-05CVE-2026-67592: It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.48%
39.8th percentile
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | qpid_protonj2 | < 1.2.0 | 1.2.0 |
| apache_software_foundation | apache_qpid_protonj2 | <= 1.1.0 | — |
| apache_software_foundation | apache_qpid_protonj2 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
ghsa_unreviewed·2026-08-05
CVE-2026-67592 [HIGH] CWE-770 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue
Red Hat
org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers
vendor_redhat·2026-08-05·CVSS 7.5
CVE-2026-67592 [HIGH] CWE-770 org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers
org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers
A flaw was found in Apache Qpid ProtonJ2. An authenticated attacker could exploit a vulnerability where the system fails to limit the number of incoming data transfers. This oversight allows the attacker to consume excessive system resources, potentially leading to a denial of service (DoS), which makes the system unavailable to legitimate users.
Package: protonj2 (Red Hat AMQ Clients) - Fix deferred
No detection rules found.
No public exploits indexed.
2026-08-05
Published