Unrated severityNVD Advisory· Published Aug 5, 2026· Updated Aug 5, 2026
Apache Qpid ProtonJ2: Incoming session flow control window can be exceeded
CVE-2026-67591
Description
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service.
This issue affects Apache Qpid ProtonJ2: through 1.1.0.
Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Affected products
1- Range: <=1.1.0
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036mitrevendor-advisory
News mentions
0No linked articles in our index yet.