As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-92560: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder
CVE-2026-92560 is a denial of service vulnerability in Apache Qpid Broker-J through version 10.1.0 that allows a pre-authentication attacker to trigger excessive memory allocation through improper type size and count handling in the AMQP 0-10 decoder. The vendor recommends upgrading to version 10.1.1 to remediate the flaw.
Why it matters: Organizations running Apache Qpid Broker-J versions 10.1.0 or earlier should upgrade immediately to 10.1.1, as unauthenticated attackers can crash the broker without credentials.
- Source published
- First seen by Cybersecurity Tracker