CVE-2026-68080

MEDIUM

Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service

Title source: cna
STIX 2.1

Description

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.

References (2)

Core 2
Core References

Scores

CVSS v3 6.5
EPSS 0.0042
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-406
Status published
Products (2)
apache/qpid_broker-j < 10.1.0
Apache Software Foundation/Apache Qpid Broker-J < 10.0.1
Published Aug 05, 2026
Tracked Since Aug 05, 2026