CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8517

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92608: Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10

CVE-2026-92608 affects Apache Qpid Broker-J through version 10.1.0, where flawed exception handling during message conversion between AMQP 1.0 and AMQP 0-10 protocols permits authenticated producers to send specially crafted messages that disrupt delivery to downstream consumers. The vulnerability carries moderate severity and stems from incomplete validation when encoding message properties during protocol translation.

Why it matters: Organizations running Apache Qpid Broker-J with AMQP protocol conversion need to upgrade to patch this denial of service vector, which an authenticated attacker can exploit to interfere with message delivery and application availability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary