pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.
https://lists.apache.org/thread/o566fhkrr3gg0lyzt24xwvz9w94oo6ro