CVE-2018-8030

HIGH

Apache Qpid Broker-J 7.0.0-7.0.4 - Denial of Service via Oversized AMQP Message

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-8030. PoCs published by dawetmaster, andikahilmy.

AI-analyzed exploit summary This repository contains source code for Apache Qpid Broker-J but lacks any exploit code or technical analysis related to CVE-2018-8030. It appears to be a partial or incomplete snapshot of the project.

Description

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.

Exploits (2)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2018-8030-qpid-broker-j-vulnerable

This repository contains source code for Apache Qpid Broker-J but lacks any exploit code or technical analysis related to CVE-2018-8030. It appears to be a partial or incomplete snapshot of the project.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache Qpid Broker-J
No auth needed
Prerequisites: None
devstral-2 · analyzed Mar 14, 2026 Full analysis →
nomisec WORKING POC
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2018-8030-qpid-broker-j-vulnerable

This repository contains the vulnerable source code for Apache Qpid Broker-J (CVE-2018-8030), specifically the BerkeleyDB storage module. The code includes the vulnerable AMQShortStringEncoding class, which is part of the deserialization vulnerability in the BDB message store.

Classification
Working Poc 90%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: Apache Qpid Broker-J (versions before 7.0.0)
No auth needed
Prerequisites: Network access to the Qpid Broker-J instance · BDB storage module enabled
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041138

Scores

CVSS v3 7.5
EPSS 0.0091
EPSS Percentile 76.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (2)
apache/qpid_broker-j 7.0.0 - 7.0.4
org.apache.qpid/apache-qpid-broker-j 7.0.0 - 7.1.0Maven
Published Jun 20, 2018
Tracked Since Feb 18, 2026