What is CVE-2026-67588?
CVE-2026-67588 allows a pre-authentication attacker to cause resource exhaustion and denial of service by exploiting unbounded symbol value caching in Apache Qpid ProtonJ2. This affects versions through 1.1.0, and users should upgrade to version 1.2.0 to fix the issue.
Azərbaycanca: CVE-2026-67588, autentifikasiyadan əvvəl hücumçunun Apache Qpid ProtonJ2-də limitsiz simvol dəyər keşləməsindən istifadə edərək resurs tükənməsi və xidmət dayanmasına səbəb olmasına imkan verir. Bu zəiflik 1.1.0 versiyasına qədər təsir göstərir. Tövsiyə olunur ki, istifadəçilər problemi aradan qaldıran 1.2.0 versiyasına yüksəltsinlər.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which software is affected by CVE-2026-67588?
CVE-2026-67588 affects Apache Qpid ProtonJ2.
How can the CVE-2026-67588 vulnerability be mitigated?
To fix the issue, users should upgrade Apache Qpid ProtonJ2 to version 1.2.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.