Skip to content
Rota Nacional

Cyber ·

CVE-2026-92608 in Apache Qpid Broker-J

A notice published on September 24, 2026 reports a moderate-severity flaw that may interrupt message delivery to AMQP 0-10 consumers. The affected component is listed through version 10.1.0.

The notice describes CVE-2026-92608 in Apache Qpid Broker-J, with moderate severity and a publication date of September 24, 2026. It lists the affected component as org.apache.qpid:qpid-broker-plugins-amqp-msg-conv-0-10-to-1-0 through version 10.1.0.

According to the text, inadequate handling of exceptions while encoding properties during conversion from AMQP 1.0 messages to AMQP 0-10 may interrupt delivery to AMQP 0-10 consumers. The described condition involves authenticated message producers and properties that the destination encoder does not handle correctly.

To assess exposure, inventory the Qpid Broker-J versions and components in use, and check whether traffic passes through this protocol conversion. Do not assume the flaw affects other components or versions beyond those identified in the notice.

Consult the original oss-sec notice and official Apache Qpid project information to verify the report, confirm its scope, and look for remediation guidance. The supplied excerpt does not specify a fixed version or mitigations; confirm those details before changing systems.

If you use an AI tool to summarize or analyze the notice, share only necessary public excerpts. Remove credentials, people’s names, addresses, and internal infrastructure details in line with your organization’s policy.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free