CVE-2026-67591
CVE-2026-67591: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-67591] Apache Qpid ProtonJ2: authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service
CVE-2026-67591Source published Source updated
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue.
- Affected products in this advisory
- Apache Qpid ProtonJ2
- Source-reported affected versions
- through 1.1.0
- Source-reported fixed versions
- 1.2.0
- Mitigation guidance
- Users are recommended to upgrade to version 1.2.0, which fixes the issue.
Red Hat
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-67591] Denial of Service via exceeding session flow control window
CVE-2026-67591Source published Source updated
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the issue. This can lead to a denial of service (DoS), making the system unavailable to legitimate users. The affected components are set to AFFECTED/DEFER as the CVSS score (6.5) is below the 7.0 threshold for immediate remediation. Note: the substring-matched artifacts are ancillary (parent POM, test driver) — the core protonj2-client library was not found via strict search. The affects are precautionary. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat AMQ…
- Affected products in this advisory
- Red Hat AMQ Broker 7
- Source-reported affected versions
- 1.1.0
- Source-reported fixed versions
- 1.2.0
- Mitigation guidance
- Ensure authenticated access to AMQP endpoints is restricted to trusted clients to limit exposure to this DoS vulnerability.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.