What is CVE-2026-66273?
CVE-2026-66273 is a vulnerability in Apache Qpid Proton-J where a pre-authentication attacker can manipulate type size/count handling to cause excessive allocation, leading to a potential denial of service (DoS). Affected versions are up to 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Azərbaycanca: CVE-2026-66273 Apache Qpid Proton-J kitabxanasında aşkar edilmiş zəiflikdir. Autentifikasiya olunmamış hücumçu type size/count əməliyyatlarını manipulyasiya edərək həddindən artıq yaddaş ayrılmasına (excessive allocation) səbəb ola bilər ki, bu da denial of service (DoS) şəraitinə gətirib çıxarır. Təsirə məruz qalan versiyalar 0.34.1-ə qədər olan buraxılışlardır. İstifadəçilərə problemi aradan qaldıran 0.35.0 versiyasına yeniləmə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which versions of Apache Qpid Proton-J are affected by CVE-2026-66273?
All versions up to 0.34.1 are affected.
What is the potential impact if CVE-2026-66273 is exploited?
This vulnerability can lead to a denial of service (DoS) condition.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.