The notice describes CVE-2026-92608 in Apache Qpid Broker-J, with moderate severity and a publication date of September 24, 2026. It lists the affected component as org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0 through version 10.1.0.
According to the text, inadequate handling of exceptions while encoding properties during conversion from AMQP 1.0 messages to AMQP 0-10 may interrupt delivery to AMQP 0-10 consumers. The described condition involves authenticated message producers and properties that the destination encoder does not handle correctly.
To assess exposure, inventory the Qpid Broker-J versions and components in use, and check whether traffic passes through this protocol conversion. Do not assume the flaw affects other components or versions beyond those identified in the notice.
Consult the original oss-sec notice and official Apache Qpid project information to verify the report, confirm its scope, and look for remediation guidance. The supplied excerpt does not specify a fixed version or mitigations; confirm those details before changing systems.
If you use an AI tool to summarize or analyze the notice, share only necessary public excerpts. Remove credentials, people’s names, addresses, and internal infrastructure details in line with your organization’s policy.