Every CVE whose affected-product data names Apache Qpid Proton-j, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (7)
CVE-2026-66274 — CVSS 7.5 (high): A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This…
CVE-2026-66257 — CVSS 7.5 (high): A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This…
CVE-2026-66273 — CVSS 7.5 (high): A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service…
CVE-2018-17187 — CVSS 7.4 (high): The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods…
CVE-2026-66275 — CVSS 6.5 (medium): An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue…
CVE-2026-66276 — CVSS 6.5 (medium): An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range…
CVE-2026-66277 — CVSS 6.5 (medium): It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause…