CVE-2026-92564
Received Received - Intake

Stack Overflow Error in Apache Qpid Broker-J

Vulnerability report for CVE-2026-92564, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: Apache Software Foundation

Description

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-25
AI Q&A
2026-09-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache qpid_broker_j to 10.1.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-674 The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a pre-authentication attacker to exploit unbounded type nesting in AMQP 0-8/0-9/0-9-1 field-table processing. This triggers a StackOverflowError, which can lead to a denial of service by crashing the Apache Qpid Broker-J service.

Detection Guidance

Detecting this vulnerability requires checking the Apache Qpid Broker-J version in use. Run the command: qpid-broker --version. If the output shows a version through 10.1.0, the system is vulnerable.

Impact Analysis

An attacker could exploit this to crash the Apache Qpid Broker-J service, causing downtime and disrupting message brokering operations. This may lead to loss of service for applications relying on the broker.

Mitigation Strategies

Upgrade Apache Qpid Broker-J to version 10.1.1 or later immediately. This version fixes the type nesting issue causing the StackOverflowError.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92564. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart