Description
An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
Weaknesses
- CWE-606 — CWE-606 Unchecked Input for Loop Condition
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Qpid Proton Dotnet | 0 to <=1.0.0 |
References
- https://lists.apache.org/thread/5ndlowz29464ytj98gz9z9ljhwnmb2hm (vendor-advisory)
Generated from the official CVE List on 05 Aug 2026 07:03 UTC.