| CVE-ID | Severity | Affected versions | Fixed versions | Summary |
|---|---|---|---|---|
| CVE-2026-67588 | Important | <= 1.1.0 | 1.2.0 and later | Unbounded symbol value caching can lead to pre-authentication resource exhaustion |
| CVE-2026-67589 | Important | <= 1.1.0 | 1.2.0 and later | Type size/count handling can lead to excessive allocation pre-authentication |
| CVE-2026-67590 | Important | <= 1.1.0 | 1.2.0 and later | Unbounded type nesting can lead to pre-authentication stackoverflow |
| CVE-2026-67591 | Important | <= 1.1.0 | 1.2.0 and later | Incoming session flow control window can be exceeded |
| CVE-2026-67592 | Important | <= 1.1.0 | 1.2.0 and later | Unable to govern the maximum number of transfer frames per incoming delivery |
See the main Security page for general information and details for other components.
Apache Qpid, Messaging built on AMQP; Copyright © 2015 The Apache Software Foundation; Licensed under the Apache License, Version 2.0; Apache Qpid, Qpid, Qpid Proton, Proton, Apache, the Apache feather logo, and the Apache Qpid project logo are trademarks of The Apache Software Foundation; All other marks mentioned may be trademarks or registered trademarks of their respective owners