HIGH
CVE-2026-67592
CVSS
7.5
Description
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue
Weakness (CWE)
CWE-770
Resource Allocation Without Limits
EPSS Score
0.48%
Probability of exploitation in next 30 days
40.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.