CVE-2026-92573

⚪ Do wiadomości

Nieprawidłowe przetwarzanie danych skompresowanych w Apache Qpid Broker-J prowadzi do wyczerpania pamięci.

CVSS
6.5
EPSS
0.4%
Exploit
none
Vendor
apache
Opis źródłowy (NVD)

Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability via processing without a decompressed-output limit. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.4%
Opublikowano (NVD)2026-09-25 09:17:06 UTC
Ostatnia modyfikacja (NVD)2026-10-05 18:01:53 UTC
Referencje