What is CVE-2026-68075?
CVE-2026-68075 allows an authenticated attacker to potentially exceed the session flow control incoming window in Apache Qpid Broker-J (through version 10.0.1), which may lead to a denial-of-service (DoS) condition. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Azərbaycanca: CVE-2026-68075 autentifikasiya olunmuş hücumçuya Apache Qpid Broker-J mesajlaşma sistemində (10.0.1 versiyasına qədər) session flow control incoming window limitini aşmağa imkan verə bilər, bu da potensial olaraq denial-of-service (DoS) vəziyyətinə səbəb olur. İstifadəçilərə bu problemi həll edən 10.1.0 versiyasına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
Which product is affected by CVE-2026-68075?
This vulnerability affects Apache Qpid Broker-J messaging system through version 10.0.1.
How can I mitigate CVE-2026-68075?
It is recommended to upgrade to Apache Qpid Broker-J version 10.1.0, which fixes the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.