Apache disclosed CVE-2026-67551 in Apache Qpid Proton-Dotnet, warning that improper handling of type size and count values can let an unauthenticated attacker trigger excessive memory allocation before authentication. The issue affects Apache Qpid Proton-Dotnet through version 1.0.0 and can be exploited to cause a denial of service by exhausting available memory.
The project rated the vulnerability important and released a fix in version 1.1.0. Organizations using Apache Qpid messaging components built on Proton-Dotnet are advised to identify exposed deployments and upgrade affected instances to 1.1.0 to mitigate the pre-authentication resource exhaustion risk.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Timothy A. Bish disclosed CVE-2026-67551 on August 4, 2026 via the oss-sec mailing list. The advisory said Apache Qpid Proton-Dotnet through version 1.0.0 is affected and recommended upgrading to version 1.1.0.
A security advisory stated that Apache Qpid Proton-Dotnet version 1.1.0 contains the fix for CVE-2026-67551, a type size/count handling flaw that could let a pre-authentication attacker trigger excessive memory allocation and potential denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.