This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/qpid-site.git

commit 6913f2362cbd6b9028c20ee6c6b74f2db6b01d6c
Author: Robbie Gemmell <[email protected]>
AuthorDate: Tue Aug 4 18:45:36 2026 +0100

    update proton-j security page to cover recent issues
---
 .../security-j.html => cves/CVE-2026-66257.html}   | 46 ++++++++------------
 .../security-j.html => cves/CVE-2026-66273.html}   | 46 ++++++++------------
 .../security-j.html => cves/CVE-2026-66274.html}   | 46 ++++++++------------
 .../security-j.html => cves/CVE-2026-66275.html}   | 46 ++++++++------------
 .../security-j.html => cves/CVE-2026-66276.html}   | 46 ++++++++------------
 .../security-j.html => cves/CVE-2026-66277.html}   | 46 ++++++++------------
 content/proton/security-j.html                     | 50 ++++++++++++++++++++--
 .../qpid-proton-j-0.35.0/release-notes.html        |  4 +-
 input/cves/CVE-2026-66257.md                       | 14 ++++++
 input/cves/CVE-2026-66273.md                       | 14 ++++++
 input/cves/CVE-2026-66274.md                       | 14 ++++++
 input/cves/CVE-2026-66275.md                       | 14 ++++++
 input/cves/CVE-2026-66276.md                       | 14 ++++++
 input/cves/CVE-2026-66277.md                       | 14 ++++++
 input/proton/security-j.md                         |  9 +++-
 .../releases/qpid-proton-j-0.35.0/release-notes.md |  3 +-
 16 files changed, 258 insertions(+), 168 deletions(-)

diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66257.html
similarity index 84%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66257.html
index a87411349..5db407d5b 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66257.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value 
caching can lead to pre-authentication resource exhaustion - Apache 
Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66257: Apache Qpid Proton-J: 
Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66257-apache-qpid-proton-j-unbounded-symbol-value-caching-can-lead-to-pre-authentication-resource-exhaustion">CVE-2026-66257:
 Apache Qpid Proton-J: Unbounded symbol value caching can lead to 
pre-authentication resource exhaustion</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage unbounded symbol value caching 
to cause resource exhaustion leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66273.html
similarity index 84%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66273.html
index a87411349..a991139da 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66273.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can 
lead to excessive allocation pre-authentication - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66273: Apache Qpid Proton-J: Type 
size/count handling can lead to excessive allocation 
pre-authentication</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66273-apache-qpid-proton-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication">CVE-2026-66273:
 Apache Qpid Proton-J: Type size/count handling can lead to excessive 
allocation pre-authentication</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type size/count handling to 
cause excessive allocation leading to potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66274.html
similarity index 85%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66274.html
index a87411349..d84e6cde3 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66274.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can 
lead to pre-authentication stackoverflow - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66274: Apache Qpid Proton-J: 
Unbounded type nesting can lead to pre-authentication stackoverflow</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66274-apache-qpid-proton-j-unbounded-type-nesting-can-lead-to-pre-authentication-stackoverflow">CVE-2026-66274:
 Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication 
stackoverflow</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66275.html
similarity index 86%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66275.html
index a87411349..65415ec15 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66275.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control 
window can be exceeded - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66275: Apache Qpid Proton-J: 
Incoming session flow control window can be exceeded</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66275-apache-qpid-proton-j-incoming-session-flow-control-window-can-be-exceeded">CVE-2026-66275:
 Apache Qpid Proton-J: Incoming session flow control window can be exceeded</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>An authenticated attacker could exceed the session flow control incoming 
window potentially leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66276.html
similarity index 84%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66276.html
index a87411349..d649d4414 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66276.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range 
handling can lead to denial of service - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66276: Apache Qpid Proton-J: 
Unbounded disposition range handling can lead to denial of service</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66276-apache-qpid-proton-j-unbounded-disposition-range-handling-can-lead-to-denial-of-service">CVE-2026-66276:
 Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial 
of service</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>An authenticated attacker can craft a disposition frame with large or 
illegal ranges causing excessive CPU usage due to naive range handling, leading 
to denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66277.html
similarity index 84%
copy from content/proton/security-j.html
copy to content/cves/CVE-2026-66277.html
index a87411349..f9595d695 100644
--- a/content/proton/security-j.html
+++ b/content/cves/CVE-2026-66277.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum 
number of transfer frames per incoming delivery - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,34 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-66277: Apache Qpid Proton-J: 
Unable to govern the maximum number of transfer frames per incoming 
delivery</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td>
-  <td>Important</td>
-  <td>0.3 to 0.29.0 inclusive</td>
-  <td>0.30.0 and later</td>
-  <td>Transport TLS wrapper hostname verification mode not implemented</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">Security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-66277-apache-qpid-proton-j-unable-to-govern-the-maximum-number-of-transfer-frames-per-incoming-delivery">CVE-2026-66277:
 Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames 
per incoming delivery</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p>
+
+<h2 id="description">Description:</h2>
+
+<p>It was not possible to govern the maximum number of transfer frames per 
incoming delivery, enabling an authenticated attacker to cause excessive 
resource usage and potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p>
+
+<p>Users are recommended to upgrade to version 0.35.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/proton/security-j.html b/content/proton/security-j.html
index a87411349..699023c98 100644
--- a/content/proton/security-j.html
+++ b/content/proton/security-j.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Proton-J - Apache Qpid&#8482;</title>
+    <title>Security - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,10 +112,12 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security - Proton-J</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid 
Proton</a></li><li>Security</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security-proton-j">Security - Proton-J</h1>
+          <h1 id="security">Security</h1>
+
+<h2 id="proton-j">Proton-J</h2>
 
 <table>
 <thead>
@@ -135,6 +137,48 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
   <td>0.30.0 and later</td>
   <td>Transport TLS wrapper hostname verification mode not implemented</td>
 </tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66257.html">CVE-2026-66257</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66273.html">CVE-2026-66273</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66274.html">CVE-2026-66274</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Unbounded type nesting can lead to pre-authentication stackoverflow</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66275.html">CVE-2026-66275</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Incoming session flow control window can be exceeded</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66276.html">CVE-2026-66276</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Unbounded disposition range handling can lead to denial of service</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-66277.html">CVE-2026-66277</a></td>
+  <td>Important</td>
+  <td>Up to 0.34.1 inclusive</td>
+  <td>0.35.0 and later</td>
+  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
+</tr>
 </tbody>
 </table>
 
diff --git a/content/releases/qpid-proton-j-0.35.0/release-notes.html 
b/content/releases/qpid-proton-j-0.35.0/release-notes.html
index ee7462f8d..9d009e653 100644
--- a/content/releases/qpid-proton-j-0.35.0/release-notes.html
+++ b/content/releases/qpid-proton-j-0.35.0/release-notes.html
@@ -123,10 +123,12 @@ about <a href="/proton/index.html">Qpid Proton</a>.</p>
 <p>For more information about this release, including download links and
 documentation, see the <a href="index.html">release overview</a>.</p>
 
+<p>See also the <a href="/proton/security-j.html">Proton-J security page</a> 
for issues addressed in this release.</p>
+
 <h2 id="new-features-and-improvements">New features and improvements</h2>
 
 <ul>
-<li><a 
href="https://issues.apache.org/jira/browse/PROTON-2609";>PROTON-2609</a> - 
[proton-j] Remove unnecessary ByteBuffer slices and duplicates from the codec 
</li>
+<li><a 
href="https://issues.apache.org/jira/browse/PROTON-2609";>PROTON-2609</a> - 
Remove unnecessary ByteBuffer slices and duplicates from the codec</li>
 <li><a 
href="https://issues.apache.org/jira/browse/PROTON-2943";>PROTON-2943</a> - 
Improve some default settings</li>
 </ul>
 
diff --git a/input/cves/CVE-2026-66257.md b/input/cves/CVE-2026-66257.md
new file mode 100644
index 000000000..9b58ae0ef
--- /dev/null
+++ b/input/cves/CVE-2026-66257.md
@@ -0,0 +1,14 @@
+## CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can 
lead to pre-authentication resource exhaustion
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description
+A pre-authentication attacker could leverage unbounded symbol value caching to 
cause resource exhaustion leading to denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-66273.md b/input/cves/CVE-2026-66273.md
new file mode 100644
index 000000000..a79ef6d73
--- /dev/null
+++ b/input/cves/CVE-2026-66273.md
@@ -0,0 +1,14 @@
+## CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to 
excessive allocation pre-authentication
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description
+A pre-authentication attacker could leverage type size/count handling to cause 
excessive allocation leading to potential denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-66274.md b/input/cves/CVE-2026-66274.md
new file mode 100644
index 000000000..49fdfb2b8
--- /dev/null
+++ b/input/cves/CVE-2026-66274.md
@@ -0,0 +1,14 @@
+## CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to 
pre-authentication stackoverflow
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description
+A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-66275.md b/input/cves/CVE-2026-66275.md
new file mode 100644
index 000000000..ffed4b0f1
--- /dev/null
+++ b/input/cves/CVE-2026-66275.md
@@ -0,0 +1,14 @@
+## CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window 
can be exceeded
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description
+An authenticated attacker could exceed the session flow control incoming 
window potentially leading to denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-66276.md b/input/cves/CVE-2026-66276.md
new file mode 100644
index 000000000..ad4953e9a
--- /dev/null
+++ b/input/cves/CVE-2026-66276.md
@@ -0,0 +1,14 @@
+## CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling 
can lead to denial of service
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description
+An authenticated attacker can craft a disposition frame with large or illegal 
ranges causing excessive CPU usage due to naive range handling, leading to 
denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-66277.md b/input/cves/CVE-2026-66277.md
new file mode 100644
index 000000000..cb26b6202
--- /dev/null
+++ b/input/cves/CVE-2026-66277.md
@@ -0,0 +1,14 @@
+## CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number 
of transfer frames per incoming delivery
+
+## Severity
+Important
+
+## Affected versions
+Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1
+
+## Description:
+It was not possible to govern the maximum number of transfer frames per 
incoming delivery, enabling an authenticated attacker to cause excessive 
resource usage and potential denial of service.
+
+This issue affects Apache Qpid Proton-J: through 0.34.1.
+
+Users are recommended to upgrade to version 0.35.0, which fixes the issue.
diff --git a/input/proton/security-j.md b/input/proton/security-j.md
index 7925e16db..3eaa6b064 100644
--- a/input/proton/security-j.md
+++ b/input/proton/security-j.md
@@ -17,11 +17,18 @@
 ;; under the License.
 ;;
 
-# Security - Proton-J
+# Security
+## Proton-J
 
 | CVE-ID | Severity | Affected versions | Fixed versions | Summary |
 | ------ | -------- | ----------------- | -------------- | ------- |
 | [CVE-2018-17187]({{site_url}}/cves/CVE-2018-17187.html) | Important | 0.3 to 
0.29.0 inclusive | 0.30.0 and later | Transport TLS wrapper hostname 
verification mode not implemented |
+| [CVE-2026-66257]({{site_url}}/cves/CVE-2026-66257.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Unbounded symbol value caching can lead 
to pre-authentication resource exhaustion |
+| [CVE-2026-66273]({{site_url}}/cves/CVE-2026-66273.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Type size/count handling can lead to 
excessive allocation pre-authentication |
+| [CVE-2026-66274]({{site_url}}/cves/CVE-2026-66274.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Unbounded type nesting can lead to 
pre-authentication stackoverflow |
+| [CVE-2026-66275]({{site_url}}/cves/CVE-2026-66275.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Incoming session flow control window can 
be exceeded |
+| [CVE-2026-66276]({{site_url}}/cves/CVE-2026-66276.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Unbounded disposition range handling can 
lead to denial of service  |
+| [CVE-2026-66277]({{site_url}}/cves/CVE-2026-66277.html) | Important | Up to 
0.34.1 inclusive  | 0.35.0 and later | Unable to govern the maximum number of 
transfer frames per incoming delivery |
 
 See the main [Security]({{site_url}}/security.html) page for general
 information and details for other components.
diff --git a/input/releases/qpid-proton-j-0.35.0/release-notes.md 
b/input/releases/qpid-proton-j-0.35.0/release-notes.md
index f481cf43a..6021942a8 100644
--- a/input/releases/qpid-proton-j-0.35.0/release-notes.md
+++ b/input/releases/qpid-proton-j-0.35.0/release-notes.md
@@ -25,10 +25,11 @@ about [Qpid Proton]({{site_url}}/proton/index.html).
 For more information about this release, including download links and
 documentation, see the [release overview](index.html).
 
+See also the [Proton-J security page]({{site_url}}/proton/security-j.html) for 
issues addressed in this release.
 
 ## New features and improvements
 
- - [PROTON-2609](https://issues.apache.org/jira/browse/PROTON-2609) - 
[proton-j] Remove unnecessary ByteBuffer slices and duplicates from the codec 
+ - [PROTON-2609](https://issues.apache.org/jira/browse/PROTON-2609) - Remove 
unnecessary ByteBuffer slices and duplicates from the codec
  - [PROTON-2943](https://issues.apache.org/jira/browse/PROTON-2943) - Improve 
some default settings
 
 ## Tasks


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to