CVE-2026-92573
Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
| CWE | CWE-409 |
| Vendor | apache software foundation |
| Product | apache qpid broker-j |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache qpid broker-j
Be the first to know when new unknown vulnerabilities affecting apache software foundation apache qpid broker-j are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache Qpid Broker-J
0 โค 10.1.0
References
Credits
Khaled Suliman of AISLE Research ๐ n0mi1k