CVE-2026-50734
published 2026-06-30CVE-2026-50734: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.80%
52.2th percentile
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | activemq | < 5.19.8 | 5.19.8 |
| apache | activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_all | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_all | >= 6.0.0 < 6.2.7 | 6.2.7 |
| apache_software_foundation | apache_activemq_client | < 5.19.8 | 5.19.8 |
| apache_software_foundation | apache_activemq_client | >= 6.0.0 < 6.2.7 | 6.2.7 |
| candlepinproject | candlepin | — | — |
| log4j_2 | log4j | — | — |
| satellite_el8 | candlepin | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache ActiveMQ up to 5.19.7/6.2.6 OpenWire denial of service (EUVD-2026-40282)
vuldb·2026-07-04·CVSS 7.5
CVE-2026-50734 [HIGH] Apache ActiveMQ up to 5.19.7/6.2.6 OpenWire denial of service (EUVD-2026-40282)
A vulnerability identified as problematic has been detected in Apache ActiveMQ up to 5.19.7/6.2.6. Impacted is an unknown function of the component OpenWire. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-50734. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
GHSA
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
ghsa_unreviewed·2026-06-30
CVE-2026-50734 [HIGH] CWE-789 Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Red Hat
Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
vendor_redhat·2026-06-30·CVSS 7.5
CVE-2026-50734 [HIGH] CWE-770 Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
A flaw was found in Apache ActiveMQ. An unauthenticated network attacker can exploit this vulnerability by sending a specially crafted WireFormatInfo frame with an excessively large size value. This unvalidated value causes the broker to attempt an oversized memory allocation during pre-authentication negotiation. Consequently, this can lead to an Out Of Memory (OOM) error, resulting in a Denial of Service (DoS) and crashing the broker.
Statement: A flaw was found in Apache ActiveMQ Classic's OpenWire protocol handling. An unauthenticated remote attacker can crash the broker by sending a crafted WireFormatInfo frame with a malicious oversized value during pre-
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [fedora-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-50734 [HIGH] CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [fedora-all]
CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from
Bugzilla
CVE-2026-50734 Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-50734 [HIGH] CVE-2026-50734 Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
CVE-2026-50734 Apache ActiveMQ Client: Apache ActiveMQ: Apache ActiveMQ All: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7
Bugzilla
CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [epel-all]
bugzilla·2026-06-30·CVSS 7.5
CVE-2026-50734 [HIGH] CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [epel-all]
CVE-2026-50734 activemq-cpp: Apache ActiveMQ: Denial of Service via crafted WireFormatInfo frame [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from 6
2026-06-30
Published