Description

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

Weaknesses

  • CWE-606 — CWE-606 Unchecked Input for Loop Condition

Affected products

VendorProductVersions
Apache Software FoundationApache Qpid Proton Dotnet0 to <=1.0.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 05 Aug 2026 07:03 UTC.