CVE-2026-68080
It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.42%
- CWE
- CWE-406
- Published
- 2026-08-05
- Last modified
- 2026-08-05
Affected products
- Apache Software Foundation Apache Qpid Broker-J
Weakness type
Related vulnerabilities
- CVE-2026-86202 — PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
- CVE-2026-54609 — QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
- CVE-2026-50045 — 'max-global-quota' reset by DNSSEC validation restarts
- CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests
- CVE-2025-58066 — DoS Vulnerability in ntpd-rs
- CVE-2021-38135 — Possible External service interaction Vulnerability in OpenText iManager
- CVE-2024-25015 — IBM MQ denial of service
- CVE-2014-125036 — drybjed ansible-ntp main.yml amplification