This is an automated email from the ASF dual-hosted git repository. asf-gitbox-commits pushed a commit to branch asf-site in repository https://gitbox.apache.org/repos/asf/qpid-site.git
commit 8de4d67174a1edffc4b4c1be81a9c1bf18286801 Author: Daniil Kirilyuk <[email protected]> AuthorDate: Tue Aug 4 18:34:28 2026 +0200 Add Qpid Broker-J 2026 CVE advisories Add advisories for CVE-2026-68060, CVE-2026-68073, CVE-2026-68074, CVE-2026-68075, CVE-2026-68077, CVE-2026-68078, and CVE-2026-68080. Update the Broker-J security page and the 10.1.0 release notes. Also document Java 25 support. --- content/components/broker-j/security.html | 49 +++++++++++ .../security.html => cves/CVE-2026-68060.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68073.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68074.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68075.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68077.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68078.html} | 95 +++++----------------- .../security.html => cves/CVE-2026-68080.html} | 95 +++++----------------- .../qpid-broker-j-10.1.0/release-notes.html | 4 + input/components/broker-j/security.md | 7 ++ input/cves/CVE-2026-68060.md | 17 ++++ input/cves/CVE-2026-68073.md | 17 ++++ input/cves/CVE-2026-68074.md | 17 ++++ input/cves/CVE-2026-68075.md | 17 ++++ input/cves/CVE-2026-68077.md | 17 ++++ input/cves/CVE-2026-68078.md | 17 ++++ input/cves/CVE-2026-68080.md | 17 ++++ .../releases/qpid-broker-j-10.1.0/release-notes.md | 6 +- 18 files changed, 316 insertions(+), 534 deletions(-) diff --git a/content/components/broker-j/security.html b/content/components/broker-j/security.html index 84d14574e..e96ab1177 100644 --- a/content/components/broker-j/security.html +++ b/content/components/broker-j/security.html @@ -184,6 +184,55 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> <td>7.0.7, 7.1.1</td> <td>Denial of Service</td> </tr> +<tr> + <td><a href="/cves/CVE-2026-68060.html">CVE-2026-68060</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Type size/count handling can lead to excessive allocation pre-authentication</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68073.html">CVE-2026-68073</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Unbounded type nesting can lead to pre-authentication stack overflow</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68074.html">CVE-2026-68074</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Unbounded symbol value caching can lead to pre-authentication resource exhaustion</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68075.html">CVE-2026-68075</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Incoming session flow control window can be exceeded</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68077.html">CVE-2026-68077</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Unbounded disposition range handling can lead to denial of service</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68078.html">CVE-2026-68078</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Unable to govern the maximum number of transfer frames per incoming delivery</td> +</tr> +<tr> + <td><a href="/cves/CVE-2026-68080.html">CVE-2026-68080</a></td> + <td>Important</td> + <td>10.0.1 and earlier</td> + <td>10.1.0</td> + <td>Unbounded echo flow responses can lead to denial of service</td> +</tr> </tbody> </table> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68060.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68060.html index 84d14574e..15cac678b 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68060.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68060-apache-qpid-broker-j-type-sizecount-handling-can-lead-to-excessive-allocation-pre-authentication">CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68073.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68073.html index 84d14574e..599cae19e 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68073.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68073-apache-qpid-broker-j-unbounded-type-nesting-can-lead-to-pre-authentication-stack-overflow">CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68074.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68074.html index 84d14574e..ccebd5c01 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68074.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68074-apache-qpid-broker-j-unbounded-symbol-value-caching-can-lead-to-pre-authentication-resource-exhaustion">CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68075.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68075.html index 84d14574e..c555e458b 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68075.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68075-apache-qpid-broker-j-incoming-session-flow-control-window-can-be-exceeded">CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68077.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68077.html index 84d14574e..8827cc1de 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68077.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68077-apache-qpid-broker-j-unbounded-disposition-range-handling-can-lead-to-denial-of-service">CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68078.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68078.html index 84d14574e..64232e57a 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68078.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68078-apache-qpid-broker-j-unable-to-govern-the-maximum-number-of-transfer-frames-per-incoming-delivery">CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/components/broker-j/security.html b/content/cves/CVE-2026-68080.html similarity index 72% copy from content/components/broker-j/security.html copy to content/cves/CVE-2026-68080.html index 84d14574e..291aef6a0 100644 --- a/content/components/broker-j/security.html +++ b/content/cves/CVE-2026-68080.html @@ -22,7 +22,7 @@ <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en"> <head> <meta charset="UTF-8"> - <title>Security - Apache Qpid™</title> + <title>CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service - Apache Qpid™</title> <meta http-equiv="X-UA-Compatible" content="IE=edge"/> <meta name="viewport" content="width=device-width, initial-scale=1.0"/> <link rel="stylesheet" href="/site.css" type="text/css" async="async"/> @@ -112,83 +112,26 @@ https://github.com/apache/qpid-proton/blob/go1{/dir}/{file}#L{line}"/> </div> <div id="-middle" class="panel"> - <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li><a href="/components/index.html">Components</a></li><li><a href="/components/broker-j/index.html">Broker-J</a></li><li>Security</li></ul> + <ul id="-path-navigation"><li><a href="/index.html">Home</a></li><li>CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service</li></ul> <div id="-middle-content"> - <h1 id="security">Security</h1> - -<table> -<thead> -<tr> - <th>CVE-ID</th> - <th>Severity</th> - <th>Affected versions</th> - <th>Fixed versions</th> - <th>Summary</th> -</tr> -</thead> -<tbody> -<tr> - <td><a href="/cves/CVE-2016-3094.html">CVE-2016-3094</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, and 6.0.2</td> - <td>6.0.3</td> - <td>Denial of service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-4432.html">CVE-2016-4432</a></td> - <td>Important</td> - <td>6.0.2 and earlier</td> - <td>6.0.3</td> - <td>Authentication bypass</td> -</tr> -<tr> - <td><a href="/cves/CVE-2016-8741.html">CVE-2016-8741</a></td> - <td>Moderate</td> - <td>6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, and 6.1.0</td> - <td>6.0.6, 6.1.1</td> - <td>Information leakage</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15701.html">CVE-2017-15701</a></td> - <td>Important</td> - <td>6.1.0, 6.1.1, 6.1.2, 6.1.3, and 6.1.4</td> - <td>6.1.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2017-15702.html">CVE-2017-15702</a></td> - <td>Important</td> - <td>0.18, 0.20, 0.22, 0.24, 0.26, 0.28, 0.30, and 0.32</td> - <td>6.0.0</td> - <td>Authentication vulnerability</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-1298.html">CVE-2018-1298</a></td> - <td>Important</td> - <td>7.0.0</td> - <td>7.0.1</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2018-8030.html">CVE-2018-8030</a></td> - <td>Important</td> - <td>7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4</td> - <td>7.0.5</td> - <td>Denial of Service</td> -</tr> -<tr> - <td><a href="/cves/CVE-2019-0200.html">CVE-2019-0200</a></td> - <td>Important</td> - <td>6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0</td> - <td>7.0.7, 7.1.1</td> - <td>Denial of Service</td> -</tr> -</tbody> -</table> - -<p>See the main <a href="/security.html">security</a> page for general -information and details for other components.</p> + <h2 id="cve-2026-68080-apache-qpid-broker-j-unbounded-echo-flow-responses-can-lead-to-denial-of-service">CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service</h2> + +<h2 id="severity">Severity</h2> + +<p>Important</p> + +<h2 id="affected-versions">Affected versions</h2> + +<p>Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1</p> + +<h2 id="description">Description</h2> + +<p>It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.</p> + +<p>This issue affects Apache Qpid Broker-J: through 10.0.1.</p> + +<p>Users are recommended to upgrade to version 10.1.0, which fixes the issue.</p> <hr/> diff --git a/content/releases/qpid-broker-j-10.1.0/release-notes.html b/content/releases/qpid-broker-j-10.1.0/release-notes.html index 4b36036cf..53392f884 100644 --- a/content/releases/qpid-broker-j-10.1.0/release-notes.html +++ b/content/releases/qpid-broker-j-10.1.0/release-notes.html @@ -123,8 +123,12 @@ and forwards messages using AMQP.</p> <p>For more information about this release, including download links and documentation, see the <a href="index.html">release overview</a>.</p> +<p>See also the <a href="/components/broker-j/security.html">Broker-J security page</a> for issues addressed in this release.</p> + <h2 id="new-features-and-improvements">New features and improvements</h2> +<p>This release adds support for Java 25.</p> + <ul> <li><a href="https://issues.apache.org/jira/browse/QPID-8013">QPID-8013</a> - [Broker-J] Reduce footprint of AMQP 1.0 protocol objects</li> <li><a href="https://issues.apache.org/jira/browse/QPID-8706">QPID-8706</a> - [Broker-J] Move AMQP-1.0 symbols declarations to a utility class</li> diff --git a/input/components/broker-j/security.md b/input/components/broker-j/security.md index efee99f1f..c80e4953e 100644 --- a/input/components/broker-j/security.md +++ b/input/components/broker-j/security.md @@ -29,6 +29,13 @@ | [CVE-2018-1298]({{site_url}}/cves/CVE-2018-1298.html) | Important | 7.0.0 | 7.0.1 | Denial of Service | | [CVE-2018-8030]({{site_url}}/cves/CVE-2018-8030.html) | Important | 7.0.0, 7.0.1, 7.0.2, 7.0.3 and 7.0.4 | 7.0.5 | Denial of Service | | [CVE-2019-0200]({{site_url}}/cves/CVE-2019-0200.html) | Important | 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.1.0, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6 and 7.1.0 | 7.0.7, 7.1.1 | Denial of Service | +| [CVE-2026-68060]({{site_url}}/cves/CVE-2026-68060.html) | Important | 10.0.1 and earlier | 10.1.0 | Type size/count handling can lead to excessive allocation pre-authentication | +| [CVE-2026-68073]({{site_url}}/cves/CVE-2026-68073.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded type nesting can lead to pre-authentication stack overflow | +| [CVE-2026-68074]({{site_url}}/cves/CVE-2026-68074.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded symbol value caching can lead to pre-authentication resource exhaustion | +| [CVE-2026-68075]({{site_url}}/cves/CVE-2026-68075.html) | Important | 10.0.1 and earlier | 10.1.0 | Incoming session flow control window can be exceeded | +| [CVE-2026-68077]({{site_url}}/cves/CVE-2026-68077.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded disposition range handling can lead to denial of service | +| [CVE-2026-68078]({{site_url}}/cves/CVE-2026-68078.html) | Important | 10.0.1 and earlier | 10.1.0 | Unable to govern the maximum number of transfer frames per incoming delivery | +| [CVE-2026-68080]({{site_url}}/cves/CVE-2026-68080.html) | Important | 10.0.1 and earlier | 10.1.0 | Unbounded echo flow responses can lead to denial of service | See the main [security]({{site_url}}/security.html) page for general diff --git a/input/cves/CVE-2026-68060.md b/input/cves/CVE-2026-68060.md new file mode 100644 index 000000000..6dd4fdf79 --- /dev/null +++ b/input/cves/CVE-2026-68060.md @@ -0,0 +1,17 @@ +## CVE-2026-68060: Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68073.md b/input/cves/CVE-2026-68073.md new file mode 100644 index 000000000..732cea69a --- /dev/null +++ b/input/cves/CVE-2026-68073.md @@ -0,0 +1,17 @@ +## CVE-2026-68073: Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68074.md b/input/cves/CVE-2026-68074.md new file mode 100644 index 000000000..f8e79291f --- /dev/null +++ b/input/cves/CVE-2026-68074.md @@ -0,0 +1,17 @@ +## CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68075.md b/input/cves/CVE-2026-68075.md new file mode 100644 index 000000000..c67e177ae --- /dev/null +++ b/input/cves/CVE-2026-68075.md @@ -0,0 +1,17 @@ +## CVE-2026-68075: Apache Qpid Broker-J: Incoming session flow control window can be exceeded + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68077.md b/input/cves/CVE-2026-68077.md new file mode 100644 index 000000000..108918001 --- /dev/null +++ b/input/cves/CVE-2026-68077.md @@ -0,0 +1,17 @@ +## CVE-2026-68077: Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68078.md b/input/cves/CVE-2026-68078.md new file mode 100644 index 000000000..ef4226820 --- /dev/null +++ b/input/cves/CVE-2026-68078.md @@ -0,0 +1,17 @@ +## CVE-2026-68078: Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/cves/CVE-2026-68080.md b/input/cves/CVE-2026-68080.md new file mode 100644 index 000000000..a816c3fe6 --- /dev/null +++ b/input/cves/CVE-2026-68080.md @@ -0,0 +1,17 @@ +## CVE-2026-68080: Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service + +## Severity + +Important + +## Affected versions + +Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1 + +## Description + +It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. + +This issue affects Apache Qpid Broker-J: through 10.0.1. + +Users are recommended to upgrade to version 10.1.0, which fixes the issue. diff --git a/input/releases/qpid-broker-j-10.1.0/release-notes.md b/input/releases/qpid-broker-j-10.1.0/release-notes.md index 20756c63b..ec74f099d 100644 --- a/input/releases/qpid-broker-j-10.1.0/release-notes.md +++ b/input/releases/qpid-broker-j-10.1.0/release-notes.md @@ -25,8 +25,12 @@ and forwards messages using AMQP. For more information about this release, including download links and documentation, see the [release overview](index.html). +See also the [Broker-J security page]({{site_url}}/components/broker-j/security.html) for issues addressed in this release. + ## New features and improvements +This release adds support for Java 25. + - [QPID-8013](https://issues.apache.org/jira/browse/QPID-8013) - [Broker-J] Reduce footprint of AMQP 1.0 protocol objects - [QPID-8706](https://issues.apache.org/jira/browse/QPID-8706) - [Broker-J] Move AMQP-1.0 symbols declarations to a utility class - [QPID-8731](https://issues.apache.org/jira/browse/QPID-8731) - [Broker-J] Security Manager removal @@ -52,5 +56,3 @@ documentation, see the [release overview](index.html). - [QPID-8745](https://issues.apache.org/jira/browse/QPID-8745) - [Broker-J] Bump caffeine dependency to the version 3.2.4 - [QPID-8746](https://issues.apache.org/jira/browse/QPID-8746) - [Broker-J] Bump hikaricp dependency to the version 7.1.0 - [QPID-8747](https://issues.apache.org/jira/browse/QPID-8747) - [Broker-J] Bump logback-gelf dependency to the version 6.1.2 - - --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
