CVE-2026-68080CWE-406

CVE-2026-68080

Medium · published August 5, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
35.4
In the wild
Unconfirmed
What it is

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid Broker-J: through 10.0.1.

Users are recommended to upgrade to version 10.1.0, which fixes the issue.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00421 · 35.4th percentile
Weakness
CWE-406 · Insufficient Control of Network Message Volume (Network Amplification)
Published
2026-08-05T11:16Z
Affected products (1)
ProductVersionsFixed in
apache/qpid_broker-j< 10.1.010.1.0
References (2)
EPSS history
Timeline
  • 05 AUG 05:51Z
    Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
    cvelistv5