PatchSiren cyber security CVE debrief
CVE-2026-92560 Apache Software Foundation CVE debrief
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.1.0. Users are recommended to upgrade to version 10.1.1, which fixes the issue. This vulnerability affects Apache Qpid Broker-J, a popular open-source message broker, and could allow an attacker to cause a denial of service. The issue requires upgrading to version 10.1.1 to fix and affects Apache Qpid Broker-J through 10.1.0.
- Vendor
- Apache Software Foundation
- Product
- Apache Qpid Broker-J
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Administrators and users of Apache Qpid Broker-J should assess their exposure and consider upgrading to version 10.1.1. This includes reviewing Apache Qpid Broker-J configurations and monitoring for potential denial of service attacks. Additionally, security teams and vulnerability management teams should review the CVE record and NVD entry to validate affected scope, severity, and vendor guidance.
Why it matters
CVE-2026-92560 is a denial of service vulnerability in Apache Qpid Broker-J that requires upgrading to version 10.1.1 to fix.
- Potential denial of service attacks
- Need to upgrade to version 10.1.1 to fix the issue
- Review and monitor Apache Qpid Broker-J configurations
Technical summary
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service in Apache Qpid Broker-J through 10.1.0. The vulnerability requires upgrading to version 10.1.1 to fix and affects Apache Qpid Broker-J through 10.1.0. The issue is related to type size/count handling and could allow an attacker to cause a denial of service. The CVE record and NVD entry provide additional information about the vulnerability and its potential impact. The vulnerability has not been modified since its publication on 2026-09-25T09:17:06.587Z.
Defensive priority
Upgrade to version 10.1.1 to fix the issue
Recommended defensive actions
- Upgrade to version 10.1.1
- Review Apache Qpid Broker-J configurations
- Monitor for potential denial of service attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record and NVD entry provide information about the vulnerability and its potential impact. The vulnerability has been reported in Apache Qpid Broker-J through 10.1.0 and requires upgrading to version 10.1.1 to fix. There is no evidence of exploitation in the wild, but defenders should verify their exposure and consider upgrading. The CVE record was published on 2026-09-25T09:17:06.587Z and has not been modified since then. The NVD entry provides additional information about the vulnerability and its potential impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-92560 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-92560
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-92560 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92560
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/dcsjw242n1bxdog29hwlg43r5611dtb7
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.