CVE-2026-49432
published 2026-06-30CVE-2026-49432: Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.58%
44.1th percentile
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure.
This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.8 | 5.19.8 |
| apache | activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_all | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_all | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_stomp | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_stomp | >= 6.0.0 < 6.2.7 | 6.2.7 |
| candlepinproject | candlepin | — | — |
| log4j_2 | log4j | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache ActiveMQ up to 5.19.7/6.2.6 Content-Length denial of service (EUVD-2026-40284)
vuldb·2026-07-03·CVSS 7.5
CVE-2026-49432 [HIGH] Apache ActiveMQ up to 5.19.7/6.2.6 Content-Length denial of service (EUVD-2026-40284)
A vulnerability was found in Apache ActiveMQ up to 5.19.7/6.2.6. It has been declared as problematic. This affects an unknown part. The manipulation of the argument Content-Length results in denial of service.
This vulnerability is reported as CVE-2026-49432. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
GHSA
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
ghsa_unreviewed·2026-06-30
CVE-2026-49432 [HIGH] CWE-20 Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure.
This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 o
Red Hat
org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
vendor_redhat·2026-06-30·CVSS 7.5
CVE-2026-49432 [HIGH] CWE-839 org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
A flaw was found in Apache ActiveMQ. A remote, unauthenticated attacker can exploit an improper input validation vulnerability by sending a specially crafted message with a negative content-length to an exposed STOMP connector. This can lead to a denial of service (DoS) condition, either by consuming excessive memory and causing an Out-Of-Memory (OOM) error or by forcing the abnormal closure of affected connections.
Statement: Red Hat products ship Apache ActiveMQ Classic components as transitive dependencies. The vulnerability is in the Classic ActiveMQ STOMP connector's content-length validation, allowing
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [epel-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49432 [HIGH] CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [epel-all]
CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error w
Bugzilla
CVE-2026-49432 org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49432 [HIGH] CVE-2026-49432 org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
CVE-2026-49432 org.apache.activemq/activemq: org.apache.activemq/activemq-all: org.apache.activemq/activemq-stomp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure.
This issue affects Apache ActiveMQ: before 5.19.8, fr
Bugzilla
CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-49432 [HIGH] CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [fedora-all]
CVE-2026-49432 activemq-cpp: Apache ActiveMQ: Denial of Service via improper input validation in STOMP connector [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error
2026-06-30
Published