← Back to search

CVE-2026-68073

7.5 HIGH

Published 2026-08-05 · Updated 2026-08-06

AI risk analysis

Summary
The flaw allows a pre-authentication attacker to cause a StackOverflowError through type nesting, potentially leading to denial of service.
Exploitability
Exploitation requires pre-authentication and specific conditions with type nesting; relatively difficult without knowledge of the exact configuration.
Blast radius
If exploited, it could result in Denial of Service for affected systems, impacting availability but not data integrity or confidentiality.
Prioritized remediation
Upgrade to Apache Qpid Broker-J version 10.1.0 immediately to address this vulnerability.
dospre-authbroker-j

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-674

Vendors

apache

Products

qpid broker-j

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.