What is CVE-2026-68078?
This vulnerability allows authenticated attackers to cause excessive resource usage and potential denial of service in Apache Qpid Broker-J by failing to govern the maximum number of transfer frames per incoming delivery. Versions through 10.0.1 are affected. Users are recommended to upgrade to version 10.1.
Azərbaycanca: Bu boşluq autentifikasiya olunmuş hücumçulara gələn çatdırılma üzrə transfer frame sayını məhdudlaşdıra bilməməklə Apache Qpid Broker-J-də resursların həddindən artıq istifadəsinə səbəb olur. 10.0.1-ə qədər versiyalar təsirlənir. İstifadəçilərə 10.1 versiyasına yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Apache
FAQ2
What type of missing restriction is exploited in CVE-2026-68078?
The failure to govern the maximum number of transfer frames per incoming delivery is exploited.
What is recommended to users to mitigate CVE-2026-68078?
Users are recommended to upgrade Apache Qpid Broker-J to version 10.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.