This is an automated email from the ASF dual-hosted git repository.

asf-gitbox-commits pushed a commit to branch asf-site
in repository https://gitbox.apache.org/repos/asf/qpid-site.git

commit 8de4d67174a1edffc4b4c1be81a9c1bf18286801
Author: Daniil Kirilyuk <[email protected]>
AuthorDate: Tue Aug 4 18:34:28 2026 +0200

    Add Qpid Broker-J 2026 CVE advisories
    
    Add advisories for CVE-2026-68060, CVE-2026-68073, CVE-2026-68074, 
CVE-2026-68075, CVE-2026-68077, CVE-2026-68078, and CVE-2026-68080.
    
    Update the Broker-J security page and the 10.1.0 release notes. Also 
document Java 25 support.
---
 content/components/broker-j/security.html          | 49 +++++++++++
 .../security.html => cves/CVE-2026-68060.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68073.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68074.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68075.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68077.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68078.html}     | 95 +++++-----------------
 .../security.html => cves/CVE-2026-68080.html}     | 95 +++++-----------------
 .../qpid-broker-j-10.1.0/release-notes.html        |  4 +
 input/components/broker-j/security.md              |  7 ++
 input/cves/CVE-2026-68060.md                       | 17 ++++
 input/cves/CVE-2026-68073.md                       | 17 ++++
 input/cves/CVE-2026-68074.md                       | 17 ++++
 input/cves/CVE-2026-68075.md                       | 17 ++++
 input/cves/CVE-2026-68077.md                       | 17 ++++
 input/cves/CVE-2026-68078.md                       | 17 ++++
 input/cves/CVE-2026-68080.md                       | 17 ++++
 .../releases/qpid-broker-j-10.1.0/release-notes.md |  6 +-
 18 files changed, 316 insertions(+), 534 deletions(-)

diff --git a/content/components/broker-j/security.html 
b/content/components/broker-j/security.html
index 84d14574e..e96ab1177 100644
--- a/content/components/broker-j/security.html
+++ b/content/components/broker-j/security.html
@@ -184,6 +184,55 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
   <td>7.0.7, 7.1.1</td>
   <td>Denial of Service</td>
 </tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Type size/count handling can lead to excessive allocation 
pre-authentication</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Unbounded type nesting can lead to pre-authentication stack overflow</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Incoming session flow control window can be exceeded</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Unbounded disposition range handling can lead to denial of service</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Unable to govern the maximum number of transfer frames per incoming 
delivery</td>
+</tr>
+<tr>
+  <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td>
+  <td>Important</td>
+  <td>10.0.1 and earlier</td>
+  <td>10.1.0</td>
+  <td>Unbounded echo flow responses can lead to denial of service</td>
+</tr>
 </tbody>
 </table>
 
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68060.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68060.html
index 84d14574e..15cac678b 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68060.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can 
lead to excessive allocation pre-authentication - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68060: Apache Qpid Broker-J: Type 
size/count handling can lead to excessive allocation 
pre-authentication</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68060-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication">CVE-2026-68060:
 Apache Qpid Broker-J: Type size/count handling can lead to excessive 
allocation pre-authentication</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type size/count handling to 
cause excessive allocation leading to potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68073.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68073.html
index 84d14574e..599cae19e 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68073.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can 
lead to pre-authentication stack overflow - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68073: Apache Qpid Broker-J: 
Unbounded type nesting can lead to pre-authentication stack overflow</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68073-apache-qpid-broker-j-unbounded-type-nesting-can-lead-to-pre-authentication-stack-overflow">CVE-2026-68073:
 Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication 
stack overflow</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68074.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68074.html
index 84d14574e..ccebd5c01 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68074.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value 
caching can lead to pre-authentication resource exhaustion - Apache 
Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68074: Apache Qpid Broker-J: 
Unbounded symbol value caching can lead to pre-authentication resource 
exhaustion</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68074-apache-qpid-broker-j-unbounded-symbol-value-caching-can-lead-to-pre-authentication-resource-exhaustion">CVE-2026-68074:
 Apache Qpid Broker-J: Unbounded symbol value caching can lead to 
pre-authentication resource exhaustion</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>A pre-authentication attacker could leverage unbounded symbol value caching 
to cause resource exhaustion leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68075.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68075.html
index 84d14574e..c555e458b 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68075.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control 
window can be exceeded - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68075: Apache Qpid Broker-J: 
Incoming session flow control window can be exceeded</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68075-apache-qpid-broker-j-incoming-session-flow-control-window-can-be-exceeded">CVE-2026-68075:
 Apache Qpid Broker-J: Incoming session flow control window can be exceeded</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>An authenticated attacker could exceed the session flow control incoming 
window potentially leading to denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68077.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68077.html
index 84d14574e..8827cc1de 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68077.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range 
handling can lead to denial of service - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68077: Apache Qpid Broker-J: 
Unbounded disposition range handling can lead to denial of service</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68077-apache-qpid-broker-j-unbounded-disposition-range-handling-can-lead-to-denial-of-service">CVE-2026-68077:
 Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial 
of service</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>An authenticated attacker can craft a disposition frame with large or 
illegal ranges causing excessive CPU usage due to naive range handling, leading 
to denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68078.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68078.html
index 84d14574e..64232e57a 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68078.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum 
number of transfer frames per incoming delivery - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68078: Apache Qpid Broker-J: 
Unable to govern the maximum number of transfer frames per incoming 
delivery</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68078-apache-qpid-broker-j-unable-to-govern-the-maximum-number-of-transfer-frames-per-incoming-delivery">CVE-2026-68078:
 Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames 
per incoming delivery</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>It was not possible to govern the maximum number of transfer frames per 
incoming delivery, enabling an authenticated attacker to cause excessive 
resource usage and potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/components/broker-j/security.html 
b/content/cves/CVE-2026-68080.html
similarity index 72%
copy from content/components/broker-j/security.html
copy to content/cves/CVE-2026-68080.html
index 84d14574e..291aef6a0 100644
--- a/content/components/broker-j/security.html
+++ b/content/cves/CVE-2026-68080.html
@@ -22,7 +22,7 @@
 <html xmlns="http://www.w3.org/1999/xhtml"; xml:lang="en">
   <head>
     <meta charset="UTF-8">
-    <title>Security - Apache Qpid&#8482;</title>
+    <title>CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses 
can lead to denial of service - Apache Qpid&#8482;</title>
     <meta http-equiv="X-UA-Compatible" content="IE=edge"/>
     <meta name="viewport" content="width=device-width, initial-scale=1.0"/>
     <link rel="stylesheet" href="/site.css" type="text/css" async="async"/>
@@ -112,83 +112,26 @@ 
https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/>
       </div>
 
       <div id="-middle" class="panel">
-        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li><a 
href="/components/index.html">Components</a></li><li><a 
href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul>
+        <ul id="-path-navigation"><li><a 
href="/index.html">Home</a></li><li>CVE-2026-68080: Apache Qpid Broker-J: 
Unbounded echo flow responses can lead to denial of service</li></ul>
 
         <div id="-middle-content">
-          <h1 id="security">Security</h1>
-
-<table>
-<thead>
-<tr>
-  <th>CVE-ID</th>
-  <th>Severity</th>
-  <th>Affected versions</th>
-  <th>Fixed versions</th>
-  <th>Summary</th>
-</tr>
-</thead>
-<tbody>
-<tr>
-  <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, and 6.0.2</td>
-  <td>6.0.3</td>
-  <td>Denial of service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td>
-  <td>Important</td>
-  <td>6.0.2 and earlier</td>
-  <td>6.0.3</td>
-  <td>Authentication bypass</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td>
-  <td>Moderate</td>
-  <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td>
-  <td>6.0.6, 6.1.1</td>
-  <td>Information leakage</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td>
-  <td>Important</td>
-  <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td>
-  <td>6.1.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td>
-  <td>Important</td>
-  <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td>
-  <td>6.0.0</td>
-  <td>Authentication vulnerability</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td>
-  <td>Important</td>
-  <td>7.0.0</td>
-  <td>7.0.1</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td>
-  <td>Important</td>
-  <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td>
-  <td>7.0.5</td>
-  <td>Denial of Service</td>
-</tr>
-<tr>
-  <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td>
-  <td>Important</td>
-  <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 
6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 
7.0.4, 7.0.5, 7.0.6 and 7.1.0</td>
-  <td>7.0.7, 7.1.1</td>
-  <td>Denial of Service</td>
-</tr>
-</tbody>
-</table>
-
-<p>See the main <a href="/security.html">security</a> page for general
-information and details for other components.</p>
+          <h2 
id="cve-2026-68080-apache-qpid-broker-j-unbounded-echo-flow-responses-can-lead-to-denial-of-service">CVE-2026-68080:
 Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of 
service</h2>
+
+<h2 id="severity">Severity</h2>
+
+<p>Important</p>
+
+<h2 id="affected-versions">Affected versions</h2>
+
+<p>Apache Qpid Broker-J 
(org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p>
+
+<h2 id="description">Description</h2>
+
+<p>It was not possible to govern the rate at which the broker would respond to 
an echo flow, enabling an authenticated attacker to cause excessive resource 
usage and potential denial of service.</p>
+
+<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p>
+
+<p>Users are recommended to upgrade to version 10.1.0, which fixes the 
issue.</p>
 
 
           <hr/>
diff --git a/content/releases/qpid-broker-j-10.1.0/release-notes.html 
b/content/releases/qpid-broker-j-10.1.0/release-notes.html
index 4b36036cf..53392f884 100644
--- a/content/releases/qpid-broker-j-10.1.0/release-notes.html
+++ b/content/releases/qpid-broker-j-10.1.0/release-notes.html
@@ -123,8 +123,12 @@ and forwards messages using AMQP.</p>
 <p>For more information about this release, including download links and
 documentation, see the <a href="index.html">release overview</a>.</p>
 
+<p>See also the <a href="/components/broker-j/security.html">Broker-J security 
page</a> for issues addressed in this release.</p>
+
 <h2 id="new-features-and-improvements">New features and improvements</h2>
 
+<p>This release adds support for Java 25.</p>
+
 <ul>
 <li><a href="https://issues.apache.org/jira/browse/QPID-8013";>QPID-8013</a> - 
[Broker-J] Reduce footprint of AMQP 1.0 protocol objects</li>
 <li><a href="https://issues.apache.org/jira/browse/QPID-8706";>QPID-8706</a> - 
[Broker-J] Move AMQP-1.0 symbols declarations to a utility class</li>
diff --git a/input/components/broker-j/security.md 
b/input/components/broker-j/security.md
index efee99f1f..c80e4953e 100644
--- a/input/components/broker-j/security.md
+++ b/input/components/broker-j/security.md
@@ -29,6 +29,13 @@
 | [CVE-2018-1298]({{site_url}}/cves/CVE-2018-1298.html) | Important | 7.0.0 | 
7.0.1 | Denial of Service |
 | [CVE-2018-8030]({{site_url}}/cves/CVE-2018-8030.html) | Important | 7.0.0, 
7.0.1, 7.0.2, 7.0.3 and 7.0.4 | 7.0.5 | Denial of Service |
 | [CVE-2019-0200]({{site_url}}/cves/CVE-2019-0200.html) | Important | 6.0.0, 
6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 
6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 
7.0.6 and 7.1.0 | 7.0.7, 7.1.1 | Denial of Service |
+| [CVE-2026-68060]({{site_url}}/cves/CVE-2026-68060.html) | Important | 10.0.1 
and earlier | 10.1.0 | Type size/count handling can lead to excessive 
allocation pre-authentication |
+| [CVE-2026-68073]({{site_url}}/cves/CVE-2026-68073.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded type nesting can lead to pre-authentication 
stack overflow |
+| [CVE-2026-68074]({{site_url}}/cves/CVE-2026-68074.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded symbol value caching can lead to 
pre-authentication resource exhaustion |
+| [CVE-2026-68075]({{site_url}}/cves/CVE-2026-68075.html) | Important | 10.0.1 
and earlier | 10.1.0 | Incoming session flow control window can be exceeded |
+| [CVE-2026-68077]({{site_url}}/cves/CVE-2026-68077.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded disposition range handling can lead to denial 
of service |
+| [CVE-2026-68078]({{site_url}}/cves/CVE-2026-68078.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unable to govern the maximum number of transfer frames 
per incoming delivery |
+| [CVE-2026-68080]({{site_url}}/cves/CVE-2026-68080.html) | Important | 10.0.1 
and earlier | 10.1.0 | Unbounded echo flow responses can lead to denial of 
service |
 
 
 See the main [security]({{site_url}}/security.html) page for general
diff --git a/input/cves/CVE-2026-68060.md b/input/cves/CVE-2026-68060.md
new file mode 100644
index 000000000..6dd4fdf79
--- /dev/null
+++ b/input/cves/CVE-2026-68060.md
@@ -0,0 +1,17 @@
+## CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to 
excessive allocation pre-authentication
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+A pre-authentication attacker could leverage type size/count handling to cause 
excessive allocation leading to potential denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68073.md b/input/cves/CVE-2026-68073.md
new file mode 100644
index 000000000..732cea69a
--- /dev/null
+++ b/input/cves/CVE-2026-68073.md
@@ -0,0 +1,17 @@
+## CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to 
pre-authentication stack overflow
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+A pre-authentication attacker could leverage type nesting to cause a 
StackOverflowError potentially leading to denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68074.md b/input/cves/CVE-2026-68074.md
new file mode 100644
index 000000000..f8e79291f
--- /dev/null
+++ b/input/cves/CVE-2026-68074.md
@@ -0,0 +1,17 @@
+## CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can 
lead to pre-authentication resource exhaustion
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+A pre-authentication attacker could leverage unbounded symbol value caching to 
cause resource exhaustion leading to denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68075.md b/input/cves/CVE-2026-68075.md
new file mode 100644
index 000000000..c67e177ae
--- /dev/null
+++ b/input/cves/CVE-2026-68075.md
@@ -0,0 +1,17 @@
+## CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window 
can be exceeded
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+An authenticated attacker could exceed the session flow control incoming 
window potentially leading to denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68077.md b/input/cves/CVE-2026-68077.md
new file mode 100644
index 000000000..108918001
--- /dev/null
+++ b/input/cves/CVE-2026-68077.md
@@ -0,0 +1,17 @@
+## CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling 
can lead to denial of service
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+An authenticated attacker can craft a disposition frame with large or illegal 
ranges causing excessive CPU usage due to naive range handling, leading to 
denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68078.md b/input/cves/CVE-2026-68078.md
new file mode 100644
index 000000000..ef4226820
--- /dev/null
+++ b/input/cves/CVE-2026-68078.md
@@ -0,0 +1,17 @@
+## CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number 
of transfer frames per incoming delivery
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+It was not possible to govern the maximum number of transfer frames per 
incoming delivery, enabling an authenticated attacker to cause excessive 
resource usage and potential denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/cves/CVE-2026-68080.md b/input/cves/CVE-2026-68080.md
new file mode 100644
index 000000000..a816c3fe6
--- /dev/null
+++ b/input/cves/CVE-2026-68080.md
@@ -0,0 +1,17 @@
+## CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can 
lead to denial of service
+
+## Severity
+
+Important
+
+## Affected versions
+
+Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) 
through 10.0.1
+
+## Description
+
+It was not possible to govern the rate at which the broker would respond to an 
echo flow, enabling an authenticated attacker to cause excessive resource usage 
and potential denial of service.
+
+This issue affects Apache Qpid Broker-J: through 10.0.1.
+
+Users are recommended to upgrade to version 10.1.0, which fixes the issue.
diff --git a/input/releases/qpid-broker-j-10.1.0/release-notes.md 
b/input/releases/qpid-broker-j-10.1.0/release-notes.md
index 20756c63b..ec74f099d 100644
--- a/input/releases/qpid-broker-j-10.1.0/release-notes.md
+++ b/input/releases/qpid-broker-j-10.1.0/release-notes.md
@@ -25,8 +25,12 @@ and forwards messages using AMQP.
 For more information about this release, including download links and
 documentation, see the [release overview](index.html).
 
+See also the [Broker-J security 
page]({{site_url}}/components/broker-j/security.html) for issues addressed in 
this release.
+
 ## New features and improvements
 
+This release adds support for Java 25.
+
  - [QPID-8013](https://issues.apache.org/jira/browse/QPID-8013) - [Broker-J] 
Reduce footprint of AMQP 1.0 protocol objects
  - [QPID-8706](https://issues.apache.org/jira/browse/QPID-8706) - [Broker-J] 
Move AMQP-1.0 symbols declarations to a utility class
  - [QPID-8731](https://issues.apache.org/jira/browse/QPID-8731) - [Broker-J] 
Security Manager removal
@@ -52,5 +56,3 @@ documentation, see the [release overview](index.html).
  - [QPID-8745](https://issues.apache.org/jira/browse/QPID-8745) - [Broker-J] 
Bump caffeine dependency to the version 3.2.4
  - [QPID-8746](https://issues.apache.org/jira/browse/QPID-8746) - [Broker-J] 
Bump hikaricp dependency to the version 7.1.0
  - [QPID-8747](https://issues.apache.org/jira/browse/QPID-8747) - [Broker-J] 
Bump logback-gelf dependency to the version 6.1.2
-
-


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to