CVE-2026-67552

Apache Qpid Proton Dotnet: Unbounded type nesting can lead to pre-authentication stackoverflow

Title source: cna
STIX 2.1

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue

References (1)

Core 1
Core References

Scores

EPSS 0.0019
EPSS Percentile 9.2%

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-674
Status published
Products (1)
Apache Software Foundation/Apache Qpid Proton Dotnet < 1.0.0
Published Aug 05, 2026
Tracked Since Aug 05, 2026