{
  "from_raw": "\"Timothy A. Bish\" <tabish@apache.org>",
  "from": "\"Timothy A. Bish\" <ta...@apache.org>",
  "gravatar": "1903d4f771f40d44895cd75d00cfc5f5",
  "to": "an...@apache.org,\n us...@qpid.apache.org",
  "subject": "CVE-2026-67589: Apache Qpid ProtonJ2: Type size/count handling can lead to excessive allocation pre-authentication",
  "message-id": "<fc404d4c-7ac2-0724-cf69-b706361e4d0a@apache.org>",
  "mid": "4d0tdj5kwdvs112p4gm2t6f9d1tod4wk",
  "permalinks": [
    "4d0tdj5kwdvs112p4gm2t6f9d1tod4wk",
    "r9dc4ccaacf68e4d3de52554353df039134c42657f73345f6e819cb34@<announce.apache.org>"
  ],
  "dbid": "9a235cdb77871639e7472f6d50cb6fcc76dc712f2cac537229495dbfe12f0d33",
  "cc": "us...@qpid.apache.org",
  "epoch": 1785869302,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/04 18:48:22",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Qpid ProtonJ2 (org.apache.qpid:protonj2) through 1.1.0\n\nDescription:\n\nA pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.\n\nThis issue affects Apache Qpid ProtonJ2: through 1.1.0.\n\nUsers are recommended to upgrade to version 1.2.0, which fixes the issue.\n\nCredit:\n\nApache Qpid security team (finder)\nxxy010605@gmail.com (reporter)\n\nReferences:\n\nhttps://qpid.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-67589\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Qpid ProtonJ2 (org.apache.qpid:protonj2) through 1.1.0\n\nDescription:\n\nA pre-authentication attacker could leverage type size/count handling to cause e",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3119,
  "id": "4d0tdj5kwdvs112p4gm2t6f9d1tod4wk"
}