Junglewise Threat Intelligence

CVE-2026-66257: Apache Qpid Proton-J unbounded symbol caching denial of service

CVE-2026-66257 · Severity: high · CVSS 7.5 · Published 2026-08-05

Vendors: Apache.

Executive brief

Apache Qpid Proton-J is a messaging protocol library used to enable communication between applications and message brokers. A pre-authentication attacker can exploit unbounded symbol value caching to exhaust server resources and cause the service to become unavailable, disrupting messaging operations and dependent applications.

Technical details

This vulnerability is a denial-of-service (DoS) attack targeting the symbol caching mechanism in Apache Qpid Proton-J. A pre-authentication attacker can send specially crafted messages that trigger unbounded accumulation of cached symbol values, exhausting memory or other system resources. The attack requires network access to the affected Proton-J service but does not require authentication. The impact is service unavailability. The vulnerability affects versions through 0.34.1, and a fix is available in version 0.35.0 or later.

Affected products

  • Apache Qpid Proton-J through 0.34.1

Timeline

  • 2026-08-05: disclosed

References