CVE-2026-92550
CVE-2026-92550: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.5
High [CVE-2026-92550] Apache Qpid Broker-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
CVE-2026-92550Source published Source updated
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
- Affected products in this advisory
- Apache Qpid Broker-J
- Source-reported affected versions
- through 10.1.0
- Source-reported fixed versions
- 10.1.1
- Mitigation guidance
- Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-92550] org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP decoder
CVE-2026-92550Source published Source updated
org.apache.qpid/qpid-broker-plugins-amqp-0-8-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Fuse 7.
- Related products — impact not confirmed
- Red Hat Fuse 7
- Source-reported affected versions
- 10.1.0
- Source-reported fixed versions
- 10.1.1
- Mitigation guidance
- Restrict network access to the AMQP messaging listeners so that only trusted client systems and application hosts can establish connections. Because this flaw is triggered during protocol decoding prior to authentication, limiting network exposure effectively reduces the attack surface. Network access can be restricted to authorized subnets using `firewalld` (adjusting for the configured AMQP listener port, such as default TCP port 5672 or 5671 for AMQPS): ```bash firewall-cmd --permanent --zone=trusted --add-source=192.168.1.0/24 firewall-cmd --permanent --remove-port=5672/tcp --zone=public firewall-cmd --reload ``` Caveats: Network filtering does not prevent attacks originating from trusted subnets or compromised internal hosts. Verify that all legitimate clients and broker instances are explicitly permitted before modifying firewall settings. Reloading firewall configurations takes effect immediately and may sever unauthorized active sessions.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.