CYBERSECURITYTRACKER
TRACKING7,719 stories in this site build1,668 vulnerability news stories in this site build
Permanent story citation

CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8520

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder

CVE-2026-92560 is a denial of service vulnerability in Apache Qpid Broker-J through version 10.1.0 that allows a pre-authentication attacker to trigger excessive memory allocation through improper type size and count handling in the AMQP 0-10 decoder. The vendor recommends upgrading to version 10.1.1 to remediate the flaw.

Why it matters: Organizations running Apache Qpid Broker-J versions 10.1.0 or earlier should upgrade immediately to 10.1.1, as unauthenticated attackers can crash the broker without credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary