What is CVE-2026-66277?
CVE-2026-66277 is a vulnerability in Apache Qpid Proton-J up to version 0.34.1 where it was not possible to limit the maximum number of transfer frames per incoming delivery. This flaw allows an authenticated attacker to cause excessive resource usage and potential denial of service. Users are recommended to upgrade to version 0.35.
Azərbaycanca: CVE-2026-66277 zəifliyi Apache Qpid Proton-J (0.34.1-ə qədər) məhsulunda aşkar edilib. Gələn çatdırılma üzrə transfer frame sayının məhdudlaşdırılmaması səbəbindən autentifikasiya olunmuş hücumçu həddindən artıq resurs istehlakına və potensial denial of service (DoS) vəziyyətinə səbəb ola bilər. İstifadəçilərə 0.35 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What causes the CVE-2026-66277 vulnerability?
The vulnerability is due to it not being possible to limit the maximum number of transfer frames per incoming delivery in Apache Qpid Proton-J.
How to mitigate CVE-2026-66277?
Users are recommended to upgrade Apache Qpid Proton-J to version 0.35.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.