Apache · Apache Qpid Broker-J · CVE-2026-92573
**Name of the Vulnerable Software and Affected Versions**
Apache Qpid Broker-J versions prior to 10.1.1
**Description**
Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message delivery, message conversion, and HTTP management JSON rendering allows authenticated message producers to exhaust memory and disrupt broker availability. This occurs because the system processes data without a decompressed-output limit.
**Recommendations**
Upgrade to version 10.1.1.