This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch asf-site in repository https://gitbox.apache.org/repos/asf/qpid-site.git
commit 15b7bbf807d5144785357520c81fb21c690e7c4e Author: Daniil Kirilyuk <[email protected]> AuthorDate: Thu Sep 24 23:45:00 2026 +0200 Add Qpid Broker-J 2026 CVE advisories --- content/components/broker-j/security.html | 42 ++++++ .../security.html => cves/CVE-2026-92550.html} | 146 ++++----------------- .../security.html => cves/CVE-2026-92560.html} | 144 +++----------------- .../security.html => cves/CVE-2026-92564.html} | 144 +++----------------- .../security.html => cves/CVE-2026-92573.html} | 146 ++++----------------- .../security.html => cves/CVE-2026-92608.html} | 144 +++----------------- .../security.html => cves/CVE-2026-92609.html} | 144 +++----------------- input/components/broker-j/security.md | 6 + input/cves/CVE-2026-92550.md | 24 ++++ input/cves/CVE-2026-92560.md | 21 +++ input/cves/CVE-2026-92564.md | 21 +++ input/cves/CVE-2026-92573.md | 24 ++++ input/cves/CVE-2026-92608.md | 21 +++ input/cves/CVE-2026-92609.md | 21 +++ 14 files changed, 310 insertions(+), 738 deletions(-) diff --git a/content/components/broker-j/security.html b/content/components/broker-j/security.html index f4f8dc896..e52035477 100644 --- a/content/components/broker-j/security.html +++ b/content/components/broker-j/security.html @@ -233,6 +233,48 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> <td>10.1.0</td> <td>Unbounded echo flow responses can lead to denial of service</td> </tr> +<tr> + <td><a href="/cves/CVE-2026-92550.html">CVE-2026-92550</a></td> + <td>Important</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-92560.html">CVE-2026-92560</a></td> + <td>Important</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-92564.html">CVE-2026-92564</a></td> + <td>Important</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-92573.html">CVE-2026-92573</a></td> + <td>Important</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-92608.html">CVE-2026-92608</a></td> + <td>Moderate</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-92609.html">CVE-2026-92609</a></td> + <td>Important</td> + <td>10.1.0 and earlier</td> + <td>10.1.1</td> + <td>Missing HTTP-session renewal after successful authentication</td> +</tr> </tbody> </table> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92550.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92550.html index f4f8dc896..17c5ddac1 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92550.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,32 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92550-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication-in-the-amqp-0-80-90-9-1-decoder">CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>Khaled Suliman of AISLE Research</p> + +<p>n0mi1k</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92560.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92560.html index f4f8dc896..b4e3188a8 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92560.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,30 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92560-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication-in-the-amqp-0-10-decoder">CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>n0mi1k</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92564.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92564.html index f4f8dc896..49a72e845 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92564.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,30 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92564-apache-qpid-broker-j-unbounded-type-nesting-can-lead-to-stack-overflow-pre-authentication-in-amqp-0-80-90-9-1-field-table-processing">CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>n0mi1k</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92573.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92573.html index f4f8dc896..d645a3c52 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92573.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,32 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92573-apache-qpid-broker-j-uncontrolled-resource-consumption-during-amqp-delivery-decompression-message-conversion-and-http-management-json-rendering">CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-core) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>Khaled Suliman of AISLE Research</p> + +<p>n0mi1k</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92608.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92608.html index f4f8dc896..81742fb7a 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92608.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,30 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92608-apache-qpid-broker-j-incomplete-property-conversion-handling-from-amqp-10-to-amqp-0-10">CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Moderate</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>n0mi1k</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-92609.html similarity index 60% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-92609.html index f4f8dc896..d67056a1a 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-92609.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,132 +112,30 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> + <h2 id="cve-2026-92609-apache-qpid-broker-j-missing-http-session-renewal-after-successful-authentication">CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication</h2> -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Type size/count handling can lead to excessive allocation pre-authentication</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Incoming session flow control window can be exceeded</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded disposition range handling can lead to denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> -</tr> -<tr> - <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> - <td>Important</td> - <td>10.0.1 and earlier</td> - <td>10.1.0</td> - <td>Unbounded echo flow responses can lead to denial of service</td> -</tr> -</tbody> -</table> +<h2 id="severity">Severity</h2> -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) through 10.1.0</p> + +<h2 id="description">Description</h2> + +<p>Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p> + +<p>Users are recommended to upgrade to version 10.1.1, which fixes the issue.</p> + +<h2 id="credit">Credit</h2> + +<p>Abhishek Kushwaha</p> <hr/> diff --git a/input/components/broker-j/security.md b/input/components/broker-j/security.md index c80e4953e..dd19f1252 100644 --- a/input/components/broker-j/security.md +++ b/input/components/broker-j/security.md @@ -36,6 +36,12 @@ | [CVE-2026-68077]({{site_url}}/cves/CVE-2026-68077.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded disposition range handling can lead to denial of service | | [CVE-2026-68078]({{site_url}}/cves/CVE-2026-68078.html) | Important | 10.0.1 and earlier | 10.1.0 | Unable to govern the maximum number of transfer frames per incoming delivery | | [CVE-2026-68080]({{site_url}}/cves/CVE-2026-68080.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded echo flow responses can lead to denial of service | +| [CVE-2026-92550]({{site_url}}/cves/CVE-2026-92550.html) | Important | 10.1.0 and earlier | 10.1.1 | Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder | +| [CVE-2026-92560]({{site_url}}/cves/CVE-2026-92560.html) | Important | 10.1.0 and earlier | 10.1.1 | Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder | +| [CVE-2026-92564]({{site_url}}/cves/CVE-2026-92564.html) | Important | 10.1.0 and earlier | 10.1.1 | Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing | +| [CVE-2026-92573]({{site_url}}/cves/CVE-2026-92573.html) | Important | 10.1.0 and earlier | 10.1.1 | Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering | +| [CVE-2026-92608]({{site_url}}/cves/CVE-2026-92608.html) | Moderate | 10.1.0 and earlier | 10.1.1 | Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 | +| [CVE-2026-92609]({{site_url}}/cves/CVE-2026-92609.html) | Important | 10.1.0 and earlier | 10.1.1 | Missing HTTP-session renewal after successful authentication | See the main [security]({{site_url}}/security.html) page for general diff --git a/input/cves/CVE-2026-92550.md b/input/cves/CVE-2026-92550.md new file mode 100644 index 000000000..cae2da43c --- /dev/null +++ b/input/cves/CVE-2026-92550.md @@ -0,0 +1,24 @@ +## CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0 + +## Description + +A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +Khaled Suliman of AISLE Research + +n0mi1k + diff --git a/input/cves/CVE-2026-92560.md b/input/cves/CVE-2026-92560.md new file mode 100644 index 000000000..19cc3d212 --- /dev/null +++ b/input/cves/CVE-2026-92560.md @@ -0,0 +1,21 @@ +## CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol) through 10.1.0 + +## Description + +A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +n0mi1k diff --git a/input/cves/CVE-2026-92564.md b/input/cves/CVE-2026-92564.md new file mode 100644 index 000000000..ac51b057c --- /dev/null +++ b/input/cves/CVE-2026-92564.md @@ -0,0 +1,21 @@ +## CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0 + +## Description + +A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +n0mi1k diff --git a/input/cves/CVE-2026-92573.md b/input/cves/CVE-2026-92573.md new file mode 100644 index 000000000..ae3e2b311 --- /dev/null +++ b/input/cves/CVE-2026-92573.md @@ -0,0 +1,24 @@ +## CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-core) through 10.1.0 + +## Description + +Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +Khaled Suliman of AISLE Research + +n0mi1k + diff --git a/input/cves/CVE-2026-92608.md b/input/cves/CVE-2026-92608.md new file mode 100644 index 000000000..73f6304ad --- /dev/null +++ b/input/cves/CVE-2026-92608.md @@ -0,0 +1,21 @@ +## CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 + +## Severity + +Moderate + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0) through 10.1.0 + +## Description + +Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 message conversion allows authenticated message producers to disrupt delivery to AMQP 0-10 consumers via message properties that the target encoder does not handle correctly. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +n0mi1k diff --git a/input/cves/CVE-2026-92609.md b/input/cves/CVE-2026-92609.md new file mode 100644 index 000000000..5c8455c2c --- /dev/null +++ b/input/cves/CVE-2026-92609.md @@ -0,0 +1,21 @@ +## CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) through 10.1.0 + +## Description + +Session fixation in HTTP management authentication allows remote attackers to gain unauthorized access to an authenticated management session via reuse of a session identifier retained across successful authentication. + +This issue affects Apache Qpid Broker-J: through 10.1.0. + +Users are recommended to upgrade to version 10.1.1, which fixes the issue. + +## Credit + +Abhishek Kushwaha --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
