CVE-2012-4458: Apache Qpid

Medium severity, CVSS 5.0. EPSS: 6.5% chance of exploitation in the next 30 days.

The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.

Affected products

  • Apache Qpid: up to and including 0.20; version 0.5 only; version 0.6 only; version 0.7 only; version 0.8 only; version 0.9 only; …

Published 2013-03-14. Last modified 2026-06-16.