| CVE-ID | Severity | Affected versions | Fixed versions | Summary |
|---|---|---|---|---|
| CVE-2018-17187 | Important | 0.3 to 0.29.0 inclusive | 0.30.0 and later | Transport TLS wrapper hostname verification mode not implemented |
| CVE-2026-66257 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
| CVE-2026-66273 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Type size/count handling can lead to excessive allocation pre-authentication |
| CVE-2026-66274 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-66275 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Incoming session flow control window can be exceeded |
| CVE-2026-66276 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unbounded disposition range handling can lead to denial of service |
| CVE-2026-66277 | Important | Up to 0.34.1 inclusive | 0.35.0 and later | Unable to govern the maximum number of transfer frames per incoming delivery |
See the main Security page for general information and details for other components.
Apache Qpid, Messaging built on AMQP; Copyright © 2015 The Apache Software Foundation; Licensed under the Apache License, Version 2.0; Apache Qpid, Qpid, Qpid Proton, Proton, Apache, the Apache feather logo, and the Apache Qpid project logo are trademarks of The Apache Software Foundation; All other marks mentioned may be trademarks or registered trademarks of their respective owners