Bug 2511326 (CVE-2026-66257)

Summary: CVE-2026-66257 qpid-proton-j: Apache Qpid Proton-J: Denial of Service via unbounded symbol value caching
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: ant, anujha, asoldano, ataylor, avibelli, bbaranow, bgeorges, bmaxwell, bstansbe, cescoffi, dandread, dbruscin, dkreling, dlofthou, ehugonne, fmariani, fmongiar, gmalinko, gsmet, istudens, ivassile, iweiss, janstey, jmartisk, jnethert, jwon, kaycoth, kvanderr, lthon, manderse, mcarlett, mosmerov, msvehla, nwallace, olubyans, pberan, pesilva, pgallagh, pjindal, pmackay, probinso, rguimara, rruss, rstancel, rstepani, rsvoboda, sbiarozk, tcunning, thjenkin, tqvarnst, vdosoudi, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Qpid Proton-J. A remote attacker, without needing to authenticate, could exploit an issue with unbounded symbol value caching. This could lead to resource exhaustion, where the system runs out of available resources, ultimately causing a denial of service (DoS). A denial of service attack makes the affected system unavailable to legitimate users.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-05 06:01:36 UTC
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service.

This issue affects Apache Qpid Proton-J: through 0.34.1.

Users are recommended to upgrade to version 0.35.0, which fixes the issue.

Comment 3 errata-xmlrpc 2026-09-03 18:34:18 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP1

Via RHSA-2026:63302 https://access.redhat.com/errata/RHSA-2026:63302

Comment 4 errata-xmlrpc 2026-09-10 16:38:17 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.14.1

Via RHSA-2026:66488 https://access.redhat.com/errata/RHSA-2026:66488

Comment 5 errata-xmlrpc 2026-09-10 23:26:18 UTC
This issue has been addressed in the following products:

  Red Hat AMQ Broker 7.13.6

Via RHSA-2026:66545 https://access.redhat.com/errata/RHSA-2026:66545