Apache qpid broker-j
This hub aggregates every CVE we track for Apache qpid broker-j, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
1
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM5CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
7
2024-092026-08
Latest CVEs
The 13 most recently published vulnerabilities affecting Apache qpid broker-j.
- CVE-2026-68080Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service6.5
- CVE-2026-68078Apache Qpid Broker-J: Unable to govern the maximum number of transfer frames per incoming delivery6.5
- CVE-2026-68077Apache Qpid Broker-J: Unbounded disposition range handling can lead to denial of service6.5
- CVE-2026-68075Apache Qpid Broker-J: Incoming session flow control window can be exceeded6.5
- CVE-2026-68073Apache Qpid Broker-J: Unbounded type nesting can lead to pre-authentication stack overflow7.5
- CVE-2026-68060Apache Qpid Broker-J: Type size/count handling can lead to excessive allocation pre-authentication7.5
- CVE-2026-68074Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion7.5
- CVE-2019-0200A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending speci...7.5
- CVE-2018-8030A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum mes...7.5
- CVE-2018-1298A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL me...5.9
- CVE-2017-15702In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a r...9.8
- CVE-2017-15701In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this t...7.5
- CVE-2016-8741The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 Authentic...7.5
Product normalization is registry-driven with AI assist and human review. How it works