What is CVE-2026-66276?
CVE-2026-66276 is a vulnerability in Apache Qpid Proton-J through version 0.34.1, where an authenticated attacker can cause denial of service by crafting a disposition frame with large or illegal ranges, leading to excessive CPU usage due to naive range handling. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Azərbaycanca: CVE-2026-66276, Apache Qpid Proton-J-nin 0.34.1-ə qədər versiyalarında autentifikasiya olunmuş hücumçunun xüsusi hazırlanmış 'disposition frame' vasitəsilə CPU-nu həddən artıq yükləyərək denial of service yaratmasına imkan verən zəiflikdir. İstifadəçilər bu problemi həll edən 0.35.0 versiyasına yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which Apache Qpid Proton-J version is affected by CVE-2026-66276?
Apache Qpid Proton-J through version 0.34.1 is affected by this vulnerability.
How should users mitigate CVE-2026-66276?
Users are recommended to upgrade to version 0.35.0, which fixes the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.