<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:apache:qpid_broker-J:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aapacheqpid_broker-j/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 19:26:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aapacheqpid_broker-j/feed.xml" rel="self" type="application/rss+xml"/><item><title>Denial of Service in Apache Qpid Broker-J via Uncontrolled Recursion</title><link>https://feed.craftedsignal.io/briefs/2026-08-qpid-dos/</link><pubDate>Thu, 06 Aug 2026 19:26:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-qpid-dos/</guid><description>Apache Qpid Broker-J versions through 10.0.1 are vulnerable to a pre-authentication denial of service attack where an attacker triggers a StackOverflowError through crafted type nesting.</description><content:encoded><![CDATA[<p>Apache Qpid Broker-J versions through 10.0.1 contain a vulnerability (CVE-2026-68073) classified as CWE-674 (Uncontrolled Recursion). This flaw allows a pre-authentication attacker to send specially crafted network requests containing deeply nested data structures to the broker. The processing of these nested types causes the application to enter an uncontrolled recursive state, ultimately resulting in a StackOverflowError. This condition forces the Apache Qpid Broker-J service to crash, creating a denial of service (DoS) condition. The vulnerability affects the AMQP 1-0 protocol implementation within the broker.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in the complete loss of availability for the targeted Apache Qpid Broker-J service. As the attack is possible without authentication, any actor with network reach to the broker's management or messaging interface can trigger the crash, disrupting critical messaging queues and downstream integrated applications.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Apache Qpid Broker-J to version 10.1.0 or later immediately to address the underlying recursion logic flaw.</li>
<li>Evaluate network access controls to ensure the Qpid Broker-J management and messaging ports are restricted to authorized source IP addresses.</li>
<li>Monitor logs for repeated service restarts or crash dumps consistent with StackOverflowError exceptions in the JVM process.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>cve-2026-68073</category><category>apache</category></item></channel></rss>