← Back to search

CVE-2026-66257

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-07

AI risk analysis

Summary
The flaw allows a pre-authentication attacker to cause resource exhaustion by leveraging unbounded symbol value caching, leading to potential denial of service.
Exploitability
Exploitation requires access to the affected version and could be moderately difficult due to the need for precise timing and input manipulation.
Blast radius
If exploited, this could result in significant service disruption affecting users relying on Apache Qpid Proton-J.
Prioritized remediation
Upgrade to Apache Qpid Proton-J version 0.35.0 immediately to mitigate the risk.
doscache-exploitapache-qpid

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-770

Vendors

apache

Products

qpid proton-j

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.