Executive brief
Apache Qpid Proton-J is a messaging protocol library used to enable communication between applications and message brokers. A pre-authentication attacker can exploit unbounded symbol value caching to exhaust server resources and cause the service to become unavailable, disrupting messaging operations and dependent applications.
Technical details
This vulnerability is a denial-of-service (DoS) attack targeting the symbol caching mechanism in Apache Qpid Proton-J. A pre-authentication attacker can send specially crafted messages that trigger unbounded accumulation of cached symbol values, exhausting memory or other system resources. The attack requires network access to the affected Proton-J service but does not require authentication. The impact is service unavailability. The vulnerability affects versions through 0.34.1, and a fix is available in version 0.35.0 or later.
Affected products
- Apache Qpid Proton-J through 0.34.1
Timeline
- 2026-08-05: disclosed