CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8519

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92564: Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing

Apache Qpid Broker-J versions through 10.1.0 contain a pre-authentication denial of service vulnerability in AMQP field-table processing. A remote attacker could exploit unbounded type nesting to trigger a stack overflow and crash the broker without requiring credentials. Remediation involves upgrading to version 10.1.1.

Why it matters: Organizations running Apache Qpid Broker-J through 10.1.0 face unauthenticated service disruption risk; apply the 10.1.1 patch immediately to restore availability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary