This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/qpid-site.git

commit 15b7bbf807d5144785357520c81fb21c690e7c4e
Author: Daniil Kirilyuk <[email protected]>
AuthorDate: Thu Sep 24 23:45:00 2026 +0200

    Add Qpid Broker-J 2026 CVE advisories
---
 content/components/broker-j/security.html          |  42 ++++++
 .../security.html => cves/CVE-2026-92550.html}     | 146 ++++-----------------
 .../security.html => cves/CVE-2026-92560.html}     | 144 +++-----------------
 .../security.html => cves/CVE-2026-92564.html}     | 144 +++-----------------
 .../security.html => cves/CVE-2026-92573.html}     | 146 ++++-----------------
 .../security.html => cves/CVE-2026-92608.html}     | 144 +++-----------------
 .../security.html => cves/CVE-2026-92609.html}     | 144 +++-----------------
 input/components/broker-j/security.md              |   6 +
 input/cves/CVE-2026-92550.md                       |  24 ++++
 input/cves/CVE-2026-92560.md                       |  21 +++
 input/cves/CVE-2026-92564.md                       |  21 +++
 input/cves/CVE-2026-92573.md                       |  24 ++++
 input/cves/CVE-2026-92608.md                       |  21 +++
 input/cves/CVE-2026-92609.md                       |  21 +++
 14 files changed, 310 insertions(+), 738 deletions(-)

diff --git a/content/components/broker-j/security.html 
b/content/components/broker-j/security.html
index f4f8dc896..e52035477 100644
--- a/content/components/broker-j/security.html
+++ b/content/components/broker-j/security.html
@@ -233,6 +233,48 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
   <td>10.1.0</td>
   <td>Unbounded echo flow responses can lead to denial of service</td>
 </tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92550.html">CVE-2026-92550</a></td>
+  <td>Important</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Type size/count handling can lead to excessive allocation 
pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92560.html">CVE-2026-92560</a></td>
+  <td>Important</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Type size/count handling can lead to excessive allocation 
pre-authentication in the AMQP 0-10 decoder</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92564.html">CVE-2026-92564</a></td>
+  <td>Important</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Unbounded type nesting can lead to stack overflow pre-authentication in 
AMQP 0-8/0-9/0-9-1 field-table processing</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92573.html">CVE-2026-92573</a></td>
+  <td>Important</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Uncontrolled resource consumption during AMQP delivery decompression, 
message conversion and HTTP management JSON rendering</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92608.html">CVE-2026-92608</a></td>
+  <td>Moderate</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-92609.html">CVE-2026-92609</a></td>
+  <td>Important</td>
+  <td>10.1.0 and earlier</td>
+  <td>10.1.1</td>
+  <td>Missing HTTP-session renewal after successful authentication</td>
+</tr>
 </tbody>
 </table>
 
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92550.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92550.html
index f4f8dc896..17c5ddac1 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92550.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can 
lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 
decoder - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,32 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92550: Apache Qpid Broker-J: Type 
size/count handling can lead to excessive allocation pre-authentication in the 
AMQP 0-8/0-9/0-9-1 decoder</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92550-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication-in-the-amqp-0-80-90-9-1-decoder">CVE-2026-92550:
 Apache Qpid Broker-J: Type size/count handling can lead to excessive 
allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type size/count handling to 
cause excessive allocation leading to potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>Khaled Suliman of AISLE Research</p>
+
+<p>n0mi1k</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92560.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92560.html
index f4f8dc896..b4e3188a8 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92560.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can 
lead to excessive allocation pre-authentication in the AMQP 0-10 decoder - 
Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,30 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92560: Apache Qpid Broker-J: Type 
size/count handling can lead to excessive allocation pre-authentication in the 
AMQP 0-10 decoder</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92560-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication-in-the-amqp-0-10-decoder">CVE-2026-92560:
 Apache Qpid Broker-J: Type size/count handling can lead to excessive 
allocation pre-authentication in the AMQP 0-10 decoder</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol) through 10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type size/count handling to 
cause excessive allocation leading to potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>n0mi1k</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92564.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92564.html
index f4f8dc896..49a72e845 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92564.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can 
lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table 
processing - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,30 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92564: Apache Qpid Broker-J: 
Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 
0-8/0-9/0-9-1 field-table processing</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92564-apache-qpid-broker-j-unbounded-type-nesting-can-lead-to-stack-overflow-pre-authentication-in-amqp-0-80-90-9-1-field-table-processing">CVE-2026-92564:
 Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow 
pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) through 10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>n0mi1k</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92573.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92573.html
index f4f8dc896..d645a3c52 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92573.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource 
consumption during AMQP delivery decompression, message conversion and HTTP 
management JSON rendering - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,32 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92573: Apache Qpid Broker-J: 
Uncontrolled resource consumption during AMQP delivery decompression, message 
conversion and HTTP management JSON rendering</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92573-apache-qpid-broker-j-uncontrolled-resource-consumption-during-amqp-delivery-decompression-message-conversion-and-http-management-json-rendering">CVE-2026-92573:
 Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery 
decompression, message conversion and HTTP management JSON rendering</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-core) through 10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>Improper handling of compressed data in the shared GZIP decompressor used 
for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and 
HTTP management JSON rendering allows authenticated message producers to 
exhaust memory and disrupt broker availability via processing without a 
decompressed-output limit.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>Khaled Suliman of AISLE Research</p>
+
+<p>n0mi1k</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92608.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92608.html
index f4f8dc896..81742fb7a 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92608.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92608: Apache Qpid Broker-J: Incomplete property 
conversion handling from AMQP 1.0 to AMQP 0-10 - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,30 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92608: Apache Qpid Broker-J: 
Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92608-apache-qpid-broker-j-incomplete-property-conversion-handling-from-amqp-10-to-amqp-0-10">CVE-2026-92608:
 Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to 
AMQP 0-10</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Moderate</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0) through 
10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 
message conversion allows authenticated message producers to disrupt delivery 
to AMQP 0-10 consumers via message properties that the target encoder does not 
handle correctly.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>n0mi1k</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-92609.html
similarity index 60%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-92609.html
index f4f8dc896..d67056a1a 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-92609.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal 
after successful authentication - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,132 +112,30 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-92609: Apache Qpid Broker-J: 
Missing HTTP-session renewal after successful authentication</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
+          <h2 
id="cve-2026-92609-apache-qpid-broker-j-missing-http-session-renewal-after-successful-authentication">CVE-2026-92609:
 Apache Qpid Broker-J: Missing HTTP-session renewal after successful 
authentication</h2>
 
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Incoming session flow control window can be exceeded</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded disposition range handling can lead to denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
-  <td>Important</td>
-  <td>10.0.1 and earlier</td>
-  <td>10.1.0</td>
-  <td>Unbounded echo flow responses can lead to denial of service</td>
-</tr>
-</tbody>
-</table>
+<h2 id="severity">Severity</h2>
 
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) 
through 10.1.0</p>
+
+<h2 id="description">Description</h2>
+
+<p>Session fixation in HTTP management authentication allows remote attackers 
to gain unauthorized access to an authenticated management session via reuse of 
a session identifier retained across successful authentication.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.1.0.</p>
+
+<p>Users are recommended to upgrade to version 10.1.1, which fixes the 
issue.</p>
+
+<h2 id="credit">Credit</h2>
+
+<p>Abhishek Kushwaha</p>
 
 
           <hr/>
diff --git a/input/components/broker-j/security.md 
b/input/components/broker-j/security.md
index c80e4953e..dd19f1252 100644
--- a/input/components/broker-j/security.md
+++ b/input/components/broker-j/security.md
@@ -36,6 +36,12 @@
 | [CVE-2026-68077]({{site_url}}/cves/CVE-2026-68077.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded disposition range handling can lead to denial 
of service |
 | [CVE-2026-68078]({{site_url}}/cves/CVE-2026-68078.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unable to govern the maximum number of transfer frames 
per incoming delivery |
 | [CVE-2026-68080]({{site_url}}/cves/CVE-2026-68080.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded echo flow responses can lead to denial of 
service |
+| [CVE-2026-92550]({{site_url}}/cves/CVE-2026-92550.html) | Important | 10.1.0 
and earlier | 10.1.1 | Type size/count handling can lead to excessive 
allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder |
+| [CVE-2026-92560]({{site_url}}/cves/CVE-2026-92560.html) | Important | 10.1.0 
and earlier | 10.1.1 | Type size/count handling can lead to excessive 
allocation pre-authentication in the AMQP 0-10 decoder |
+| [CVE-2026-92564]({{site_url}}/cves/CVE-2026-92564.html) | Important | 10.1.0 
and earlier | 10.1.1 | Unbounded type nesting can lead to stack overflow 
pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing |
+| [CVE-2026-92573]({{site_url}}/cves/CVE-2026-92573.html) | Important | 10.1.0 
and earlier | 10.1.1 | Uncontrolled resource consumption during AMQP delivery 
decompression, message conversion and HTTP management JSON rendering |
+| [CVE-2026-92608]({{site_url}}/cves/CVE-2026-92608.html) | Moderate | 10.1.0 
and earlier | 10.1.1 | Incomplete property conversion handling from AMQP 1.0 to 
AMQP 0-10 |
+| [CVE-2026-92609]({{site_url}}/cves/CVE-2026-92609.html) | Important | 10.1.0 
and earlier | 10.1.1 | Missing HTTP-session renewal after successful 
authentication |
 
 
 See the main [security]({{site_url}}/security.html) page for general
diff --git a/input/cves/CVE-2026-92550.md b/input/cves/CVE-2026-92550.md
new file mode 100644
index 000000000..cae2da43c
--- /dev/null
+++ b/input/cves/CVE-2026-92550.md
@@ -0,0 +1,24 @@
+## CVE-2026-92550: Apache Qpid Broker-J: Type size/count handling can lead to 
excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) 
through 10.1.0
+
+## Description
+
+A pre-authentication attacker could leverage type size/count handling to cause 
excessive allocation leading to potential denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+Khaled Suliman of AISLE Research
+
+n0mi1k
+
diff --git a/input/cves/CVE-2026-92560.md b/input/cves/CVE-2026-92560.md
new file mode 100644
index 000000000..19cc3d212
--- /dev/null
+++ b/input/cves/CVE-2026-92560.md
@@ -0,0 +1,21 @@
+## CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to 
excessive allocation pre-authentication in the AMQP 0-10 decoder
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-10-protocol) 
through 10.1.0
+
+## Description
+
+A pre-authentication attacker could leverage type size/count handling to cause 
excessive allocation leading to potential denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+n0mi1k
diff --git a/input/cves/CVE-2026-92564.md b/input/cves/CVE-2026-92564.md
new file mode 100644
index 000000000..ac51b057c
--- /dev/null
+++ b/input/cves/CVE-2026-92564.md
@@ -0,0 +1,21 @@
+## CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to 
stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol) 
through 10.1.0
+
+## Description
+
+A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+n0mi1k
diff --git a/input/cves/CVE-2026-92573.md b/input/cves/CVE-2026-92573.md
new file mode 100644
index 000000000..ae3e2b311
--- /dev/null
+++ b/input/cves/CVE-2026-92573.md
@@ -0,0 +1,24 @@
+## CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption 
during AMQP delivery decompression, message conversion and HTTP management JSON 
rendering
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-core) through 10.1.0
+
+## Description
+
+Improper handling of compressed data in the shared GZIP decompressor used for 
AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP 
management JSON rendering allows authenticated message producers to exhaust 
memory and disrupt broker availability via processing without a 
decompressed-output limit.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+Khaled Suliman of AISLE Research
+
+n0mi1k
+
diff --git a/input/cves/CVE-2026-92608.md b/input/cves/CVE-2026-92608.md
new file mode 100644
index 000000000..73f6304ad
--- /dev/null
+++ b/input/cves/CVE-2026-92608.md
@@ -0,0 +1,21 @@
+## CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion 
handling from AMQP 1.0 to AMQP 0-10
+
+## Severity
+
+Moderate
+
+## Affected versions
+
+Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0) through 10.1.0
+
+## Description
+
+Improper handling of property-encoding exceptions in AMQP 1.0-to-AMQP 0-10 
message conversion allows authenticated message producers to disrupt delivery 
to AMQP 0-10 consumers via message properties that the target encoder does not 
handle correctly.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+n0mi1k
diff --git a/input/cves/CVE-2026-92609.md b/input/cves/CVE-2026-92609.md
new file mode 100644
index 000000000..5c8455c2c
--- /dev/null
+++ b/input/cves/CVE-2026-92609.md
@@ -0,0 +1,21 @@
+## CVE-2026-92609: Apache Qpid Broker-J: Missing HTTP-session renewal after 
successful authentication
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-management-http) 
through 10.1.0
+
+## Description
+
+Session fixation in HTTP management authentication allows remote attackers to 
gain unauthorized access to an authenticated management session via reuse of a 
session identifier retained across successful authentication.
+
+This issue affects Apache Qpid Broker-J: through 10.1.0.
+
+Users are recommended to upgrade to version 10.1.1, which fixes the issue.
+
+## Credit
+
+Abhishek Kushwaha


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to