CVE-2026-67553
Received Received - Intake

Denial of Service in Apache Qpid Proton-Dotnet

Vulnerability report for CVE-2026-67553, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-05

Last updated on: 2026-08-05

Assigner: Apache Software Foundation

Description

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-05
Last Modified
2026-08-05
Generated
2026-08-05
AI Q&A
2026-08-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache qpid_proton_dotnet to 1.0.0 (exc)
apache qpid_proton_dotnet to 1.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated attacker to exceed the session flow control incoming window, which could cause a denial of service by overwhelming the system's ability to handle incoming data.

Detection Guidance

This vulnerability is specific to Apache Qpid Proton-Dotnet and requires authentication to exploit. Detection involves checking the installed version of Apache Qpid Proton-Dotnet. If the version is 1.0.0 or earlier, the system is vulnerable. Upgrade to version 1.1.0 or later to mitigate the risk.

Impact Analysis

The impact includes potential service disruption or unavailability due to the denial of service, affecting systems using Apache Qpid Proton-Dotnet versions up to 1.0.0.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It is a denial-of-service issue in Apache Qpid Proton-Dotnet that could disrupt service availability but does not involve unauthorized data access or processing violations.

Mitigation Strategies

Upgrade Apache Qpid Proton-Dotnet to version 1.1.0 or later to address the session flow control vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67553. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart