← Back to search

CVE-2026-67589

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-07

AI risk analysis

Summary
The flaw involves improper type size/count handling that can lead to excessive memory allocation, potentially causing a denial of service.
Exploitability
Exploitation requires pre-authentication access and specific conditions on message sizes or counts; it is moderately difficult.
Blast radius
If exploited, the impact could be significant as it may disrupt services relying on affected Apache Qpid ProtonJ2 versions.
Prioritized remediation
Upgrade to Apache Qpid ProtonJ2 version 1.2.0 immediately to address this issue.
dosmemory-overflowupgrade

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-789

Vendors

apache

Products

qpid protonj2

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.