CVE-2012-2145: Apache Qpid

Medium severity, CVSS 5.0. EPSS: 4.2% chance of exploitation in the next 30 days.

Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of incomplete connections.

Affected products

  • Apache Qpid: up to and including 0.17; version 0.6 only; version 0.7 only; version 0.8 only; version 0.9 only; version 0.10 only; …

Published 2012-09-28. Last modified 2026-06-16.