CVE-2026-92573: memory exhaustion risk in Apache Qpid Broker-J
A notice published on September 24, 2026 rates as important a flaw that may exhaust Apache Qpid Broker-J memory when processing compressed data.
The CVE-2026-92573 notice says improper handling of compressed data in a shared GZIP decompressor may exhaust memory and harm Apache Qpid Broker-J availability. The described risk involves authenticated message producers and processing without a limit on decompressed output.
The affected component is org.apache.qpid:qpid-broker-core, in versions up to 10.1.0. Cited paths include delivery of AMQP 0-8, 0-9, 0-9-1, and 0-10 messages, message conversion, and JSON rendering in HTTP management. The text is an automatic translation of a post in the oss-sec feed, attributed to Daniil Kirilyuk and dated September 24, 2026. Consult the original post and project advisories to verify scope, versions, and remediation guidance before acting. If using AI to study the notice or apply changes, do not submit credentials, personal data, or unnecessary internal details; review any output before executing it.