{"id":"CVE-2026-67551","published":"2026-08-05T06:16:39.313","lastModified":"2026-08-07T20:43:29.637","description":"pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-789"],"vendors":["apache"],"products":["qpid proton-dotnet"],"references":[{"url":"https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro","tags":["Vendor Advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2026/08/04/22","tags":["Third Party Advisory"]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw involves improper type size/count handling which can lead to excessive memory allocation, potentially causing a denial of service. This matters because attackers can exploit it without authentication to disrupt services.","exploitability":"Exploitation requires pre-authentication access and knowledge of the specific input conditions that trigger excessive memory usage; relatively low effort for skilled attackers.","blast_radius":"If exploited, this could impact availability by crashing or significantly degrading performance of affected Apache Qpid Proton-Dotnet services.","remediation":"Upgrade to version 1.1.0 to address the issue and mitigate potential denial of service attacks.","tags":["dos","memory-overflow","upgrade"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:56:33.837Z"}}