{
  "from_raw": "\"Timothy A. Bish\" <tabish@apache.org>",
  "from": "\"Timothy A. Bish\" <ta...@apache.org>",
  "gravatar": "1903d4f771f40d44895cd75d00cfc5f5",
  "to": "an...@apache.org,\n us...@qpid.apache.org",
  "subject": "CVE-2026-67554: Apache Qpid Proton Dotnet: Unbounded disposition range handling can lead to denial of service",
  "message-id": "<c2504675-3bbb-0b7a-29d1-32a7c92452b7@apache.org>",
  "mid": "8px9h05dj30xw8mrzs3dylk1sdm1swvy",
  "permalinks": [
    "8px9h05dj30xw8mrzs3dylk1sdm1swvy",
    "rcf7e16c8dfb581b7a344ed212fc85fd66428b69d3f78dd1768a86f50@<announce.apache.org>"
  ],
  "dbid": "11f5a01862804cd453719f72213a4bb0ec652cfd521521a028fca93c9ac4ce8c",
  "cc": "us...@qpid.apache.org",
  "epoch": 1785869107,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/08/04 18:45:07",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Proton Dotnet (org.apache.qpid) through 1.0.0\n\nDescription:\n\nAn authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service.\n\nThis issue affects Apache Qpid Proton-Dotnet: through 1.0.0.\n\nUsers are recommended to upgrade to version 1.1.0, which fixes the issue.\n\nReferences:\n\nhttps://qpid.apache.org/\nhttps://www.cve.org/CVERecord?id=CVE-2026-67554\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Qpid Proton Dotnet (org.apache.qpid) through 1.0.0\n\nDescription:\n\nAn authenticated attacker can craft a disposition frame with large or illegal ranges",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3152,
  "id": "8px9h05dj30xw8mrzs3dylk1sdm1swvy"
}