What is CVE-2026-66274?
CVE-2026-66274 is a vulnerability in Apache Qpid Proton-J up to version 0.34.1. A pre-authentication attacker can leverage type nesting to cause a StackOverflowError, potentially leading to a denial of service (DoS). Users are recommended to upgrade to version 0.35.0 to fix the issue.
Azərbaycanca: CVE-2026-66274 Apache Qpid Proton-J kitabxanasında 0.34.1-ə qədər versiyalarda aşkarlanmış boşluqdur. Autentifikasiyadan əvvəl hücumçu type nesting istifadə edərək StackOverflowError yaradaraq denial of service (DoS) vəziyyəti yarada bilər. 0.35.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which versions of the Apache Qpid Proton-J library are affected by CVE-2026-66274?
This vulnerability affects Apache Qpid Proton-J versions up to 0.34.1.
What version are users recommended to upgrade to in order to fix CVE-2026-66274?
Users are recommended to upgrade to version 0.35.0 to fix this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.