openwall.com
http://www.openwall.com/lists/oss-security/2026/08/04/12 CVE-2026-66276
MEDIUM
Apache Qpid Proton-J: Unbounded disposition range handling can lead to denial of service
Record summary
CVE-2026-66276 has a selected CVSS score of 6.5 (medium).
Description
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Apache Qpid Proton-JBrowse Apache Software Foundation / Apache Qpid Proton-Jorg.apache.qpid:proton-jDefault status: unaffected | CVE List | Through 0.34.1 | affected |
References
3lists.apache.orgVendor advisory
https://lists.apache.org/thread/14nj0lpsqpnd3q0hw0t0tw44qvdo1jc2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-66276