CVE-2026-41043
published 2026-04-24CVE-2026-41043: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.56%
42.9th percentile
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.
This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.
Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.6 | 5.19.6 |
| apache | activemq | >= 6.0.0 < 6.2.5 | 6.2.5 |
| apache | activemq_web | < 5.19.6 | 5.19.6 |
| apache | activemq_web | >= 6.0.0 < 6.2.5 | 6.2.5 |
| apache_software_foundation | apache_activemq | < 5.19.6 | 5.19.6 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.2.5 | 6.2.5 |
| apache_software_foundation | apache_activemq_web | < 5.19.6 | 5.19.6 |
| apache_software_foundation | apache_activemq_web | >= 6.0.0 < 6.2.5 | 6.2.5 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache ActiveMQ: Apache ActiveMQ Web: Apache ActiveMQ: Information disclosure via Cross-Site Scripting in web console
vendor_redhat·2026-04-24·CVSS 6.5
CVE-2026-41043 [MEDIUM] CWE-79 Apache ActiveMQ: Apache ActiveMQ Web: Apache ActiveMQ: Information disclosure via Cross-Site Scripting in web console
Apache ActiveMQ: Apache ActiveMQ Web: Apache ActiveMQ: Information disclosure via Cross-Site Scripting in web console
A flaw was found in Apache ActiveMQ and Apache ActiveMQ Web. An authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability by injecting malicious HTML into a Java Message Service (JMS) selector field and overriding the content type to HTML. This allows the attacker to display malicious content to other users browsing queues in the web console, potentially leading to information disclosure or execution of arbitrary client-side scripts.
Package: activemq-client (Red Hat AMQ Broker 7) - Fix deferred
Package: activemq-client (Red Hat build of Apache Camel for Spring Boot 4) - Fix deferred
Package: activemq-client-jakarta (Red Hat build of Apache Camel for
GHSA
Apache ActiveMQ Vulnerable to Cross-site Scripting
ghsa·2026-04-24
CVE-2026-41043 [MEDIUM] CWE-79 Apache ActiveMQ Vulnerable to Cross-site Scripting
Apache ActiveMQ Vulnerable to Cross-site Scripting
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.
This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.
Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.
GHSA
GHSA-2jp3-2923-9h52: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web
ghsa_unreviewed·2026-04-24
CVE-2026-41043 CWE-79 GHSA-2jp3-2923-9h52: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.
This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.
Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.
VulDB
Apache ActiveMQ up to 5.19.5/6.2.4 cross site scripting
vuldb·2026-04-23·CVSS 6.5
CVE-2026-41043 [MEDIUM] Apache ActiveMQ up to 5.19.5/6.2.4 cross site scripting
A vulnerability was found in Apache ActiveMQ up to 5.19.5/6.2.4 and classified as problematic. This affects an unknown part. Such manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-41043. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-04-24
Published