Qpid Broker-J
Apache · 21 CVEs
Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP…
Sep 25, 2026
Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-…
Sep 25, 2026
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 dec…
Sep 25, 2026
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/…
Sep 25, 2026
Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication
Sep 25, 2026
Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10
Sep 25, 2026
Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
Aug 5, 2026
Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery
Aug 5, 2026
Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service
Aug 5, 2026
Apache Qpid Broker-J: Incoming session flow control window can be exceeded
Aug 5, 2026
Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow
Aug 5, 2026
Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication
Aug 5, 2026
Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion
Aug 5, 2026
qpid-java: Malformed AMQP 0-8 to 0-10 commands resulting in a Denial of Service
Mar 6, 2019
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 o…
Jun 19, 2018
qpid-java: Incorrect implementation of some SASL mechanisms can allow a remote unauthenticated attacker to cause a deni…
Feb 9, 2018
qpid-java: Authentication vulnerability on HTTP ports
Dec 1, 2017
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame s…
Dec 1, 2017
qpid-java: Information leakage via specific AuthenticationProviders
May 15, 2017
qpid-java: Authentication bypass
Jun 1, 2016
qpid-java: crash in PLAIN SASL handler on malformed SASL response
Jun 1, 2016
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-92573 | Apache Qpid Broker-J: Uncontrolled resource consumption during AMQP delivery decompression, message conversion and HTTP management JSON rendering | MEDIUM | 0.29% | Sep 25, 2026 |
| CVE-2026-92564 | Apache Qpid Broker-J: Unbounded type nesting can lead to stack overflow pre-authentication in AMQP 0-8/0-9/0-9-1 field-table processing | HIGH | 0.37% | Sep 25, 2026 |
| CVE-2026-92560 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-10 decoder | HIGH | 0.37% | Sep 25, 2026 |
| CVE-2026-92550 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication in the AMQP 0-8/0-9/0-9-1 decoder | HIGH | 0.37% | Sep 25, 2026 |
| CVE-2026-92609 | Apache Qpid Broker-J: Missing HTTP-session renewal after successful authentication | CRITICAL | 0.38% | Sep 25, 2026 |
| CVE-2026-92608 | Apache Qpid Broker-J: Incomplete property conversion handling from AMQP 1.0 to AMQP 0-10 | HIGH | 0.32% | Sep 25, 2026 |
| CVE-2026-68080 | Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service | MEDIUM | 0.65% | Aug 5, 2026 |
| CVE-2026-68078 | Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery | MEDIUM | 0.65% | Aug 5, 2026 |
| CVE-2026-68077 | Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service | MEDIUM | 0.65% | Aug 5, 2026 |
| CVE-2026-68075 | Apache Qpid Broker-J: Incoming session flow control window can be exceeded | MEDIUM | 0.65% | Aug 5, 2026 |
| CVE-2026-68073 | Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow | HIGH | 0.77% | Aug 5, 2026 |
| CVE-2026-68060 | Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication | HIGH | 0.77% | Aug 5, 2026 |
| CVE-2026-68074 | Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion | HIGH | 0.77% | Aug 5, 2026 |
| CVE-2019-0200 | qpid-java: Malformed AMQP 0-8 to 0-10 commands resulting in a Denial of Service | HIGH | 3.82% | Mar 6, 2019 |
| CVE-2018-8030 | A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with… | HIGH | 3.93% | Jun 19, 2018 |
| CVE-2018-1298 | qpid-java: Incorrect implementation of some SASL mechanisms can allow a remote unauthenticated attacker to cause a denial of service | HIGH | 2.33% | Feb 9, 2018 |
| CVE-2017-15702 | qpid-java: Authentication vulnerability on HTTP ports | CRITICAL | 6.21% | Dec 1, 2017 |
| CVE-2017-15701 | In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthe… | HIGH | 4.39% | Dec 1, 2017 |
| CVE-2016-8741 | qpid-java: Information leakage via specific AuthenticationProviders | HIGH | 6.30% | May 15, 2017 |
| CVE-2016-4432 | qpid-java: Authentication bypass | CRITICAL | 8.15% | Jun 1, 2016 |
| CVE-2016-3094 | qpid-java: crash in PLAIN SASL handler on malformed SASL response | MEDIUM | 7.83% | Jun 1, 2016 |
Showing 1 to 21 of 21 CVEs