Skip to content

[GHSA-wr2r-m36x-734x] A pre-authentication attacker could leverage type size... - #9404

Open
Ankush-Pathak wants to merge 1 commit into
Ankush-Pathak/advisory-improvement-9404from
Ankush-Pathak-GHSA-wr2r-m36x-734x
Open

[GHSA-wr2r-m36x-734x] A pre-authentication attacker could leverage type size...#9404
Ankush-Pathak wants to merge 1 commit into
Ankush-Pathak/advisory-improvement-9404from
Ankush-Pathak-GHSA-wr2r-m36x-734x

Conversation

@Ankush-Pathak

Copy link
Copy Markdown
Contributor

Updates

  • Affected products
  • Summary

Comments
Adding affected Maven coordinates for org.apache.qpid:proton-j.

The Apache CNA record states the issue affects Proton-J through 0.34.1 and is
fixed in 0.35.0, with packageName org.apache.qpid:proton-j:
https://www.cve.org/CVERecord?id=CVE-2026-66273

Range: < 0.35.0, patched 0.35.0. Maven Central confirms 0.34.1 is the last
release before 0.35.0:
https://repo1.maven.org/maven2/org/apache/qpid/proton-j/0.35.0/

Sources:
https://lists.apache.org/thread/z34s9v5w05qk4qqtz5fs3v9wpxz6fnbh
http://www.openwall.com/lists/oss-security/2026/08/04/9
https://qpid.apache.org/releases/qpid-proton-j-0.35.0/index.html

@github-actions
github-actions Bot changed the base branch from main to Ankush-Pathak/advisory-improvement-9404 September 8, 2026 09:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant