What is CVE-2026-67554?
CVE-2026-67554 allows an authenticated attacker to craft a disposition frame with large or illegal ranges, causing excessive CPU usage due to naive range handling in Apache Qpid Proton-Dotnet through version 1.0.0, leading to denial of service. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Azərbaycanca: CVE-2026-67554, autentifikasiya olunmuş hücumçuya Apache Qpid Proton-Dotnet 1.0.0-a qədər versiyalarda zəif diapazon emalı səbəbindən xüsusi hazırlanmış 'disposition frame' ilə yüksək CPU istifadəsi yaradaraq xidmət (DoS) rəddi etməyə imkan verir. Bu problemi həll edən 1.1.0 versiyasına yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which product is affected by CVE-2026-67554?
This vulnerability affects Apache Qpid Proton-Dotnet through version 1.0.0.
How can one protect against CVE-2026-67554?
Upgrading to version 1.1.0 is recommended, as this version fixes the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.