← Back to search

CVE-2026-67588

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-07

AI risk analysis

Summary
The flaw involves unbounded symbol value caching which can lead to resource exhaustion and denial of service. This matters because attackers can exploit it without authentication.
Exploitability
Exploitation requires pre-authentication access but is relatively straightforward given the right conditions.
Blast radius
If exploited, this could significantly impact availability by causing service disruptions for affected systems.
Prioritized remediation
Upgrade to Apache Qpid ProtonJ2 version 1.2.0 immediately to address the issue.
dosauthlesscache

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-770

Vendors

apache

Products

qpid protonj2

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.