CVE-2026-67552: Apache Qpid Proton-Dotnet

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue

Affected products

  • Apache Qpid Proton-Dotnet: before 1.1.0 (fixed in 1.1.0)

Published 2026-08-05. Last modified 2026-08-07.