What is CVE-2026-68074?
A vulnerability in Apache Qpid Broker-J allows a pre-authentication attacker to cause resource exhaustion via unbounded symbol value caching, leading to a denial of service. This affects versions up to 10.0.1, and users are advised to upgrade to version 10.1.0 to fix the issue.
Azərbaycanca: CVE-2026-68074, Apache Qpid Broker-J proqramında autentifikasiyadan əvvəlki mərhələdə (pre-authentication) zəiflik aşkar edilib. Təcavüzkar simvol dəyərlərinin qeyri-məhdud keşlənməsi (unbounded symbol value caching) vasitəsilə resurs tükənməsinə (resource exhaustion) səbəb olaraq xidmətin dayanmasına (denial of service) nail ola bilər. Bu problem 10.0.1 daxil olmaqla versiyalara təsir edir və istifadəçilərə 10.1.0 versiyasına yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What type of attack does CVE-2026-68074 enable in Apache Qpid Broker-J?
This vulnerability allows a pre-authentication attacker to cause resource exhaustion, leading to a denial of service.
Which version should Apache Qpid Broker-J users upgrade to in order to fix CVE-2026-68074?
Users are advised to upgrade to version 10.1.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.