CVE-2026-92560
CVE-2026-92560: 2 tracked advisory records across Apache, Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Apache
1 advisory- Advisory severityHigh7.5
High [CVE-2026-92560] Apache Qpid Broker-J: pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service
CVE-2026-92560Source published Source updated
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue.
- Affected products in this advisory
- Apache Qpid Broker-J
- Source-reported affected versions
- through 10.1.0
- Source-reported fixed versions
- 10.1.1
- Mitigation guidance
- Users are recommended to upgrade to version 10.1.1, which fixes the issue.
Red Hat
1 advisory- Advisory severityHigh7.5
High [CVE-2026-92560] org.apache.qpid/qpid-broker-plugins-amqp-0-10-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP 0-10 decoder
CVE-2026-92560Source published Source updated
org.apache.qpid/qpid-broker-plugins-amqp-0-10-protocol: Apache Qpid Broker-J: Denial of Service via excessive memory allocation in AMQP 0-10 decoder. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected product named by the advisory: Red Hat Fuse 7.
- Related products — impact not confirmed
- Red Hat Fuse 7
- Source-reported affected versions
- 10.1.0
- Source-reported fixed versions
- 10.1.1
- Mitigation guidance
- Restrict access to the AMQP broker service port (default TCP port 5672 or 5671) to trusted networks or localhost using firewall controls. To limit access to authorized client subnets using firewalld: 1. Remove unrestricted public access to the AMQP port: # firewall-cmd --zone=public --remove-port=5672/tcp --permanent 2. Allow access only from trusted source IP addresses or subnets: # firewall-cmd --zone=trusted --add-source=<TRUSTED_IP_OR_CIDR> --permanent 3. Apply the firewall configuration: # firewall-cmd --reload Caveat: Blocking public broker port access will prevent any external or unlisted clients from connecting to the messaging service. Verify that all legitimate application endpoints and client networks are added to the trusted zone. Warning: Reloading firewall rules may temporarily disrupt active network sessions or client connections.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.