{
  "from_raw": "Daniil Kirilyuk <dakirily@apache.org>",
  "from": "Daniil Kirilyuk <da...@apache.org>",
  "gravatar": "1d0f9a82be052875a8bd9261147569c3",
  "to": "an...@apache.org,\n us...@qpid.apache.org",
  "subject": "CVE-2026-68074: Apache Qpid Broker-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
  "message-id": "<fd243d2c-cd7c-34ff-ade0-8ce4ea3080a1@apache.org>",
  "mid": "2xdjqpnxm9hpk5sccydy3zk4ptbssyg5",
  "permalinks": [
    "2xdjqpnxm9hpk5sccydy3zk4ptbssyg5",
    "r1468352641a7a9ac1a7614a653aced182f7e63febbe87b0ce9d9d056@<announce.apache.org>"
  ],
  "dbid": "8439983b2c4164c86e83e9b0c35ffc6ee87cbf97dcc418ca45a2b6c70d403b2d",
  "cc": "us...@qpid.apache.org",
  "epoch": 1785867264,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/04 18:14:24",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1\n\nDescription:\n\nA pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Broker-J: through 10.0.1.\n\nUsers are recommended to upgrade to version 10.1.0, which fixes the issue.\n\nReferences:\n\nhttps://qpid.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-68074\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Broker-J (org.apache.qpid:qpid-broker-plugins-amqp-1-0-protocol) through 10.0.1\n\nDescription:\n\nA pre-authentication attacker could leverage unbou",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3073,
  "id": "2xdjqpnxm9hpk5sccydy3zk4ptbssyg5"
}