<Vulnerability name="CVE-2026-67592">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-05T05:44:18</PublicDate>
    <Bugzilla id="2511341" url="https://bugzilla.redhat.com/show_bug.cgi?id=2511341" xml:lang="en:us">
org.apache.qpid/protonj2: Apache Qpid ProtonJ2: Denial of Service via uncontrolled incoming data transfers
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-770</CWE>
    <Details xml:lang="en:us" source="Mitre">
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service.

This issue affects Apache Qpid ProtonJ2: through 1.1.0.

Users are recommended to upgrade to version 1.2.0, which fixes the issue
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Apache Qpid ProtonJ2. An authenticated attacker could exploit a vulnerability where the system fails to limit the number of incoming data transfers. This oversight allows the attacker to consume excessive system resources, potentially leading to a denial of service (DoS), which makes the system unavailable to legitimate users.
    </Details>
    <PackageState cpe="cpe:/a:redhat:amq_clients:2023">
        <ProductName>Red Hat AMQ Clients</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>protonj2</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-67592
https://nvd.nist.gov/vuln/detail/CVE-2026-67592
https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz
    </References>
</Vulnerability>