CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8518

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92573: Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering

CVE-2026-92573 affects Apache Qpid Broker-J through version 10.1.0 and allows authenticated message producers to consume excessive memory through improper handling of compressed data in the shared GZIP decompressor. The vulnerability affects AMQP 0-8, 0-9, 0-9-1, and 0-10 message delivery, message conversion, and HTTP management JSON rendering. An attacker can disrupt broker availability by triggering uncontrolled resource consumption.

Why it matters: Organizations running Apache Qpid Broker-J must patch immediately, as authenticated users can crash the message broker and cause service disruption; verify your version and apply updates from the Apache Qpid project.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary