High [CVE-2026-92550] org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP decoder
This high-severity Red Hat Linux advisory covers CVE-2026-92550; related products: Red Hat Fuse 7.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP decoder. Red Hat rates this important (CVSS 7.5).
Weakness: CWE-770.
Affected product named by the advisory: Red Hat Fuse 7.
- 10.1.0
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Mitigation checklist
- Restrict network access to the AMQP messaging listeners so that only trusted client systems and application hosts can establish connections. Because this flaw is triggered during protocol decoding prior to authentication, limiting network exposure effectively reduces the attack surface. Network access can be restricted to authorized subnets using `firewalld` (adjusting for the configured AMQP listener port, such as default TCP port 5672 or 5671 for AMQPS): ```bash firewall-cmd --permanent --zone=trusted --add-source=192.168.1.0/24 firewall-cmd --permanent --remove-port=5672/tcp --zone=public firewall-cmd --reload ``` Caveats: Network filtering does not prevent attacks originating from trusted subnets or compromised internal hosts. Verify that all legitimate clients and broker instances are explicitly permitted before modifying firewall settings. Reloading firewall configurations takes effect immediately and may sever unauthorized active sessions.
Official advisory · high-confidence parse· fetched 8 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.