{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/apache-qpid-broker-j/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:qpid_broker-j:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-68073"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Apache Qpid Broker-J"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","cve-2026-68073","apache"],"_cs_type":"advisory","_cs_vendors":["Apache Software Foundation"],"content_html":"\u003cp\u003eApache Qpid Broker-J versions through 10.0.1 contain a vulnerability (CVE-2026-68073) classified as CWE-674 (Uncontrolled Recursion). This flaw allows a pre-authentication attacker to send specially crafted network requests containing deeply nested data structures to the broker. The processing of these nested types causes the application to enter an uncontrolled recursive state, ultimately resulting in a StackOverflowError. This condition forces the Apache Qpid Broker-J service to crash, creating a denial of service (DoS) condition. The vulnerability affects the AMQP 1-0 protocol implementation within the broker.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in the complete loss of availability for the targeted Apache Qpid Broker-J service. As the attack is possible without authentication, any actor with network reach to the broker's management or messaging interface can trigger the crash, disrupting critical messaging queues and downstream integrated applications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Apache Qpid Broker-J to version 10.1.0 or later immediately to address the underlying recursion logic flaw.\u003c/li\u003e\n\u003cli\u003eEvaluate network access controls to ensure the Qpid Broker-J management and messaging ports are restricted to authorized source IP addresses.\u003c/li\u003e\n\u003cli\u003eMonitor logs for repeated service restarts or crash dumps consistent with StackOverflowError exceptions in the JVM process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T19:26:24Z","date_published":"2026-08-06T19:26:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-qpid-dos/","summary":"Apache Qpid Broker-J versions through 10.0.1 are vulnerable to a pre-authentication denial of service attack where an attacker triggers a StackOverflowError through crafted type nesting.","title":"Denial of Service in Apache Qpid Broker-J via Uncontrolled Recursion","url":"https://feed.craftedsignal.io/briefs/2026-08-qpid-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Apache Qpid Broker-J","version":"https://jsonfeed.org/version/1.1"}