This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch asf-site in repository https://gitbox.apache.org/repos/asf/qpid-site.git
commit 6913f2362cbd6b9028c20ee6c6b74f2db6b01d6c Author: Robbie Gemmell <[email protected]> AuthorDate: Tue Aug 4 18:45:36 2026 +0100 update proton-j security page to cover recent issues --- .../security-j.html => cves/CVE-2026-66257.html} | 46 ++++++++------------ .../security-j.html => cves/CVE-2026-66273.html} | 46 ++++++++------------ .../security-j.html => cves/CVE-2026-66274.html} | 46 ++++++++------------ .../security-j.html => cves/CVE-2026-66275.html} | 46 ++++++++------------ .../security-j.html => cves/CVE-2026-66276.html} | 46 ++++++++------------ .../security-j.html => cves/CVE-2026-66277.html} | 46 ++++++++------------ content/proton/security-j.html | 50 ++++++++++++++++++++-- .../qpid-proton-j-0.35.0/release-notes.html | 4 +- input/cves/CVE-2026-66257.md | 14 ++++++ input/cves/CVE-2026-66273.md | 14 ++++++ input/cves/CVE-2026-66274.md | 14 ++++++ input/cves/CVE-2026-66275.md | 14 ++++++ input/cves/CVE-2026-66276.md | 14 ++++++ input/cves/CVE-2026-66277.md | 14 ++++++ input/proton/security-j.md | 9 +++- .../releases/qpid-proton-j-0.35.0/release-notes.md | 3 +- 16 files changed, 258 insertions(+), 168 deletions(-) diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66257.html similarity index 84% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66257.html index a87411349..5db407d5b 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66257.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66257-apache-qpid-proton-j-unbounded-symbol-value-caching-can-lead-to-pre-authentication-resource-exhaustion">CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66273.html similarity index 84% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66273.html index a87411349..a991139da 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66273.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66273-apache-qpid-proton-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication">CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66274.html similarity index 85% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66274.html index a87411349..d84e6cde3 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66274.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66274-apache-qpid-proton-j-unbounded-type-nesting-can-lead-to-pre-authentication-stackoverflow">CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66275.html similarity index 86% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66275.html index a87411349..65415ec15 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66275.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66275-apache-qpid-proton-j-incoming-session-flow-control-window-can-be-exceeded">CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description</h2> + +<p>An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66276.html similarity index 84% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66276.html index a87411349..d649d4414 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66276.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66276-apache-qpid-proton-j-unbounded-disposition-range-handling-can-lead-to-denial-of-service">CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description</h2> + +<p>An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/cves/CVE-2026-66277.html similarity index 84% copy from content/proton/security-j.html copy to content/cves/CVE-2026-66277.html index a87411349..f9595d695 100644 --- a/content/proton/security-j.html +++ b/content/cves/CVE-2026-66277.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,34 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2018-17187.html">CVE-2018-17187</a></td> - <td>Important</td> - <td>0.3 to 0.29.0 inclusive</td> - <td>0.30.0 and later</td> - <td>Transport TLS wrapper hostname verification mode not implemented</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">Security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-66277-apache-qpid-proton-j-unable-to-govern-the-maximum-number-of-transfer-frames-per-incoming-delivery">CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1</p> + +<h2 id="description">Description:</h2> + +<p>It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.</p> + +<p>This issue affects Apache Qpid Proton-J: through 0.34.1.</p> + +<p>Users are recommended to upgrade to version 0.35.0, which fixes the issue.</p> <hr/> diff --git a/content/proton/security-j.html b/content/proton/security-j.html index a87411349..699023c98 100644 --- a/content/proton/security-j.html +++ b/content/proton/security-j.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Proton-J - Apache Qpid™</title> + <title>Security - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,10 +112,12 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security - Proton-J</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/proton/index.html">Qpid Proton</a></li><li>Security</li></ul> <div id="-middle-content"> - <h1 id="security-proton-j">Security - Proton-J</h1> + <h1 id="security">Security</h1> + +<h2 id="proton-j">Proton-J</h2> <table> <thead> @@ -135,6 +137,48 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> <td>0.30.0 and later</td> <td>Transport TLS wrapper hostname verification mode not implemented</td> </tr> +<tr> + <td><a href="/cves/CVE-2026-66257.html">CVE-2026-66257</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-66273.html">CVE-2026-66273</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Type size/count handling can lead to excessive allocation pre-authentication</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-66274.html">CVE-2026-66274</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Unbounded type nesting can lead to pre-authentication stackoverflow</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-66275.html">CVE-2026-66275</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Incoming session flow control window can be exceeded</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-66276.html">CVE-2026-66276</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Unbounded disposition range handling can lead to denial of service</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-66277.html">CVE-2026-66277</a></td> + <td>Important</td> + <td>Up to 0.34.1 inclusive</td> + <td>0.35.0 and later</td> + <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> +</tr> </tbody> </table> diff --git a/content/releases/qpid-proton-j-0.35.0/release-notes.html b/content/releases/qpid-proton-j-0.35.0/release-notes.html index ee7462f8d..9d009e653 100644 --- a/content/releases/qpid-proton-j-0.35.0/release-notes.html +++ b/content/releases/qpid-proton-j-0.35.0/release-notes.html @@ -123,10 +123,12 @@ about <a href="/proton/index.html">Qpid Proton</a>.</p> <p>For more information about this release, including download links and documentation, see the <a href="index.html">release overview</a>.</p> +<p>See also the <a href="/proton/security-j.html">Proton-J security page</a> for issues addressed in this release.</p> + <h2 id="new-features-and-improvements">New features and improvements</h2> <ul> -<li><a href="https://issues.apache.org/jira/browse/PROTON-2609">PROTON-2609</a> - [proton-j] Remove unnecessary ByteBuffer slices and duplicates from the codec </li> +<li><a href="https://issues.apache.org/jira/browse/PROTON-2609">PROTON-2609</a> - Remove unnecessary ByteBuffer slices and duplicates from the codec</li> <li><a href="https://issues.apache.org/jira/browse/PROTON-2943">PROTON-2943</a> - Improve some default settings</li> </ul> diff --git a/input/cves/CVE-2026-66257.md b/input/cves/CVE-2026-66257.md new file mode 100644 index 000000000..9b58ae0ef --- /dev/null +++ b/input/cves/CVE-2026-66257.md @@ -0,0 +1,14 @@ +## CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description +A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/cves/CVE-2026-66273.md b/input/cves/CVE-2026-66273.md new file mode 100644 index 000000000..a79ef6d73 --- /dev/null +++ b/input/cves/CVE-2026-66273.md @@ -0,0 +1,14 @@ +## CVE-2026-66273: Apache Qpid Proton-J: Type size/count handling can lead to excessive allocation pre-authentication + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description +A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/cves/CVE-2026-66274.md b/input/cves/CVE-2026-66274.md new file mode 100644 index 000000000..49fdfb2b8 --- /dev/null +++ b/input/cves/CVE-2026-66274.md @@ -0,0 +1,14 @@ +## CVE-2026-66274: Apache Qpid Proton-J: Unbounded type nesting can lead to pre-authentication stackoverflow + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description +A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/cves/CVE-2026-66275.md b/input/cves/CVE-2026-66275.md new file mode 100644 index 000000000..ffed4b0f1 --- /dev/null +++ b/input/cves/CVE-2026-66275.md @@ -0,0 +1,14 @@ +## CVE-2026-66275: Apache Qpid Proton-J: Incoming session flow control window can be exceeded + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description +An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/cves/CVE-2026-66276.md b/input/cves/CVE-2026-66276.md new file mode 100644 index 000000000..ad4953e9a --- /dev/null +++ b/input/cves/CVE-2026-66276.md @@ -0,0 +1,14 @@ +## CVE-2026-66276: Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description +An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/cves/CVE-2026-66277.md b/input/cves/CVE-2026-66277.md new file mode 100644 index 000000000..cb26b6202 --- /dev/null +++ b/input/cves/CVE-2026-66277.md @@ -0,0 +1,14 @@ +## CVE-2026-66277: Apache Qpid Proton-J: Unable to govern the maximum number of transfer frames per incoming delivery + +## Severity +Important + +## Affected versions +Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1 + +## Description: +It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. + +This issue affects Apache Qpid Proton-J: through 0.34.1. + +Users are recommended to upgrade to version 0.35.0, which fixes the issue. diff --git a/input/proton/security-j.md b/input/proton/security-j.md index 7925e16db..3eaa6b064 100644 --- a/input/proton/security-j.md +++ b/input/proton/security-j.md @@ -17,11 +17,18 @@ ;; under the License. ;; -# Security - Proton-J +# Security +## Proton-J | CVE-ID | Severity | Affected versions | Fixed versions | Summary | | ------ | -------- | ----------------- | -------------- | ------- | | [CVE-2018-17187]({{site_url}}/cves/CVE-2018-17187.html) | Important | 0.3 to 0.29.0 inclusive | 0.30.0 and later | Transport TLS wrapper hostname verification mode not implemented | +| [CVE-2026-66257]({{site_url}}/cves/CVE-2026-66257.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded symbol value caching can lead to pre-authentication resource exhaustion | +| [CVE-2026-66273]({{site_url}}/cves/CVE-2026-66273.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Type size/count handling can lead to excessive allocation pre-authentication | +| [CVE-2026-66274]({{site_url}}/cves/CVE-2026-66274.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded type nesting can lead to pre-authentication stackoverflow | +| [CVE-2026-66275]({{site_url}}/cves/CVE-2026-66275.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Incoming session flow control window can be exceeded | +| [CVE-2026-66276]({{site_url}}/cves/CVE-2026-66276.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded disposition range handling can lead to denial of service | +| [CVE-2026-66277]({{site_url}}/cves/CVE-2026-66277.html) | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unable to govern the maximum number of transfer frames per incoming delivery | See the main [Security]({{site_url}}/security.html) page for general information and details for other components. diff --git a/input/releases/qpid-proton-j-0.35.0/release-notes.md b/input/releases/qpid-proton-j-0.35.0/release-notes.md index f481cf43a..6021942a8 100644 --- a/input/releases/qpid-proton-j-0.35.0/release-notes.md +++ b/input/releases/qpid-proton-j-0.35.0/release-notes.md @@ -25,10 +25,11 @@ about [Qpid Proton]({{site_url}}/proton/index.html). For more information about this release, including download links and documentation, see the [release overview](index.html). +See also the [Proton-J security page]({{site_url}}/proton/security-j.html) for issues addressed in this release. ## New features and improvements - - [PROTON-2609](https://issues.apache.org/jira/browse/PROTON-2609) - [proton-j] Remove unnecessary ByteBuffer slices and duplicates from the codec + - [PROTON-2609](https://issues.apache.org/jira/browse/PROTON-2609) - Remove unnecessary ByteBuffer slices and duplicates from the codec - [PROTON-2943](https://issues.apache.org/jira/browse/PROTON-2943) - Improve some default settings ## Tasks --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
