CVE-2026-39304
published 2026-04-10CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.90%
55.4th percentile
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.
Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.
This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4.
Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.4 | 5.19.4 |
| apache | activemq | >= 6.0.0 < 6.2.4 | 6.2.4 |
| apache | activemq_broker | < 5.19.4 | 5.19.4 |
| apache | activemq_broker | >= 6.0.0 < 6.2.4 | 6.2.4 |
| apache_software_foundation | apache_activemq | < 5.19.4 | 5.19.4 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.2.4 | 6.2.4 |
| apache_software_foundation | apache_activemq_all | < 5.19.4 | 5.19.4 |
| apache_software_foundation | apache_activemq_all | >= 6.0.0 < 6.2.4 | 6.2.4 |
| apache_software_foundation | apache_activemq_broker | < 5.19.4 | 5.19.4 |
| apache_software_foundation | apache_activemq_broker | >= 6.0.0 < 6.2.4 | 6.2.4 |
| apache_software_foundation | apache_activemq_client | < 5.19.4 | 5.19.4 |
| apache_software_foundation | apache_activemq_client | >= 6.0.0 < 6.2.4 | 6.2.4 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
vendor_redhat·2026-04-10·CVSS 7.5
CVE-2026-39304 [HIGH] CWE-770 Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
A flaw was found in Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ. A remote attacker can exploit this vulnerability by rapidly triggering Transport Layer Security (TLS) version 1.3 handshake KeyUpdates. This improper handling of KeyUpdates causes the broker to exhaust its memory in the SSL engine, leading to a Denial of Service (DoS) condition where the service becomes unavailable.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
P
GHSA
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
ghsa·2026-04-10
CVE-2026-39304 [HIGH] CWE-400 Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
Apache ActiveMQ: Denial of Service via Out of Memory vulnerability
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.
Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.
This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 befo
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-39304 log4j: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion [fedora-all]
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-39304 [HIGH] CVE-2026-39304 log4j: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion [fedora-all]
CVE-2026-39304 log4j: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-39304 Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-39304 [HIGH] CVE-2026-39304 Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
CVE-2026-39304 Apache ActiveMQ Client: Apache ActiveMQ Broker: Apache ActiveMQ: Apache ActiveMQ: Denial of Service due to TLSv1.3 KeyUpdate memory exhaustion
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS.
Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.
This issue affects Apache ActiveMQ Client: bef
https://activemq.apache.org/security-advisories.data/CVE-2026-39304-announcement.txthttp://www.openwall.com/lists/oss-security/2026/04/09/17https://access.redhat.com/security/cve/CVE-2026-39304https://bugzilla.redhat.com/show_bug.cgi?id=2457275https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-39304.json
2026-04-10
Published