Skip to content
Rota Nacional

Cyber ·

CVE-2026-92560: denial-of-service flaw in Apache Qpid Broker-J

An alert published on September 24, 2026 describes excessive allocation before authentication in Apache Qpid Broker-J’s AMQP 0-10 decoder. Versions through 10.1.0 are affected; the stated recommendation is to update to 10.1.1.

Classified as important and published on September 24, 2026, the alert covers CVE-2026-92560 in Apache Qpid Broker-J’s AMQP 0-10 protocol plugin. The description says versions through and including 10.1.0 are affected.

According to the notice, handling the size and type count can trigger excessive allocation. An unauthenticated attacker could exploit this condition, potentially causing a denial of service.

The stated recommendation is to update to version 10.1.1, which fixes the issue. First identify the installed version and confirm whether the affected component is in use; then plan and apply the update according to the project’s official procedures.

To verify the alert, consult the original oss-sec mailing-list post and compare the CVE identifier, affected versions, and fix with official Apache Qpid advisories. If using AI to summarize logs or study the incident, remove internal data and credentials before submitting any material.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free