{
  "from_raw": "Robbie Gemmell <robbie@apache.org>",
  "from": "Robbie Gemmell <ro...@apache.org>",
  "gravatar": "38e6778b28eb00ba7dd1b66469d62456",
  "to": "an...@apache.org,\n us...@qpid.apache.org",
  "subject": "CVE-2026-66257: Apache Qpid Proton-J: Unbounded symbol value caching can lead to pre-authentication resource exhaustion",
  "message-id": "<d47383ff-64e4-1dd3-8c0b-70cef54f591f@apache.org>",
  "mid": "6n6d6bkpyjz28k2849wtnzxnvx9cw1xg",
  "permalinks": [
    "6n6d6bkpyjz28k2849wtnzxnvx9cw1xg",
    "r84b4bc9db30f3d8f4b923323f4654d3f0d7d777ad464cbef35d5a073@<announce.apache.org>"
  ],
  "dbid": "cca422a674cdeb4138d80bda9e788ea82f3f65048b46b8b8ce6b530473b06b04",
  "cc": "us...@qpid.apache.org",
  "epoch": 1785865737,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/04 17:48:57",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1\n\nDescription:\n\nA pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.\n\nThis issue affects Apache Qpid Proton-J: through 0.34.1.\n\nUsers are recommended to upgrade to version 0.35.0, which fixes the issue.\n\nReferences:\n\nhttps://qpid.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-66257\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Proton-J (org.apache.qpid:proton-j) through 0.34.1\n\nDescription:\n\nA pre-authentication attacker could leverage unbounded symbol value caching to ",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3124,
  "id": "6n6d6bkpyjz28k2849wtnzxnvx9cw1xg"
}