What is CVE-2026-67589?
CVE-2026-67589 is a vulnerability in Apache Qpid ProtonJ2 versions through 1.1.0. A pre-authentication attacker can exploit improper handling of type size/count to trigger excessive memory allocation, potentially leading to a denial of service. Users are advised to upgrade to version 1.2.0.
Azərbaycanca: CVE-2026-67589, Apache Qpid ProtonJ2-nin 1.1.0-a qədər versiyalarında aşkar edilmiş boşluqdur. Autentifikasiyadan əvvəl hücumçu tip ölçüsü/sayı idarəetməsindəki zəiflikdən istifadə edərək həddindən artıq yaddaş ayırmasına səbəb ola bilər ki, bu da denial of service vəziyyətinə gətirib çıxarır. İstifadəçilərə 1.2.0 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which software product is affected by CVE-2026-67589?
CVE-2026-67589 affects Apache Qpid ProtonJ2 versions up to 1.1.0.
How to protect against CVE-2026-67589?
Users are advised to upgrade Apache Qpid ProtonJ2 to version 1.2.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.