maven package report

Is org.apache.qpid:apache-qpid-broker-j safe?

3 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
3.4%

chance of exploitation in the next 30 days

xyz score
3.5

CyberXYZ composite, out of 10

fig. 01 — GHSA-c9h6-xhg9-xxrv, the advisory selected below

// advisories

GHSA-c9h6-xhg9-xxrv

HIGHCVE-2019-0200

A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending specially crafted commands using AMQP protocol versions below 1.0 (AMQP 0-8, 0-9, 0-91 and 0-10). Users of Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 utilizing AMQP protocols 0-8, 0-9, 0-

Affected
< 7.0.7, = 7.1.0
Fixed in
7.0.7
Weakness
CWE-20
Published
2019-03-07
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:58 UTC. The most recent advisory here was published 2019-03-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is org.apache.qpid:apache-qpid-broker-j safe? maven package security report | CyberXYZ