Qpid Proton J
by Apache
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-66274 | imp | 0.49 | 7.5 | — | Aug 5, 2026 | org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting | ||
| CVE-2026-66277 | mod | 0.42 | 6.5 | — | Aug 5, 2026 | org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames | ||
| CVE-2018-17187 | Hig | 0.41 | 7.4 | 0.03 | Nov 13, 2018 | The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer… |
- risk 0.49cvss 7.5epss —
org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via unbounded type nesting
- risk 0.42cvss 6.5epss —
org.apache.qpid/proton-j: Apache Qpid Proton-J: Denial of Service via uncontrolled transfer frames
- risk 0.41cvss 7.4epss 0.03
The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer…