Apache Activemq vulnerabilities
72 known vulnerabilities affecting apache/activemq.
Total CVEs
72
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
6
Severity breakdown
CRITICAL13HIGH29MEDIUM27LOW3
Vulnerabilities
Page 2 of 4
CVE-2021-21341P2HIGHCVSS 7.5fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21341 [HIGH] CWE-400 CVE-2021-21341: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. N
nvd
CVE-2021-21350P2CRITICALCVSS 9.8fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21350 [CRITICAL] CWE-434 CVE-2021-21350: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist lim
nvd
CVE-2021-21347P2CRITICALCVSS 9.8fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21347 [CRITICAL] CWE-434 CVE-2021-21347: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fr
nvd
CVE-2021-21343P3HIGHCVSS 7.5fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21343 [HIGH] CWE-73 CVE-2021-21343: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the proc
nvd
CVE-2026-45505P2HIGHCVSS 8.8fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-45505 [HIGH] CVE-2026-45505: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Non-parenthesized discovery wrappers such as `masterslave:vm://...,...`
and `static:vm://...` incorrectly pass validation allowing bypass of fix in CVE-2026-34197.
Original description from CVE-
nvd
CVE-2026-41044P2HIGHCVSS 8.8fixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-41044 [HIGH] CWE-20 CVE-2026-41044: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.
An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM tr
nvd
CVE-2025-66168P3HIGHCVSS 8.8fixed in 5.19.2≥ 6.0.0, ≤ 6.1.8+1 more2026-03-04
CVE-2025-66168 [HIGH] CWE-190 CVE-2025-66168: WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releas
WARNING:
Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.
See the following for more details:
https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt
https://www.cve.org/CVERecord?id=CVE-2026-40046
Original Report:
Apache ActiveMQ does not properly validate the remaining len
nvd
CVE-2014-3600P3CRITICALCVSS 9.8v5.0.0v5.1.0+16 more2017-10-27
CVE-2014-3600 [CRITICAL] CWE-611 CVE-2014-3600: XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
nvdosv
CVE-2020-13947P3MEDIUMCVSS 6.1fixed in 5.15.14≥ 5.16.0, < 5.16.12021-02-08
CVE-2020-13947 [MEDIUM] CWE-79 CVE-2020-13947: An instance of a cross-site scripting vulnerability was identified to be present in the web based ad
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
nvdosv
CVE-2026-49157P3HIGHCVSS 8.8fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-49157 [HIGH] CWE-276 CVE-2026-49157: Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ:
Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue
nvd
CVE-2026-42588P3HIGHCVSS 8.1fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-42588 [HIGH] CWE-20 CVE-2026-42588: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache
nvd
CVE-2021-26117P3HIGHCVSS 7.5≥ 5.15.0, < 5.15.14≥ 5.16.0, < 5.16.12021-01-27
CVE-2021-26117 [HIGH] CWE-287 CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
nvdosv
CVE-2021-21348P3HIGHCVSS 7.5fixed in 5.15.14v5.16.0+1 more2021-03-23
CVE-2021-21348 [HIGH] CWE-400 CVE-2021-21348: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited t
nvd
CVE-2014-3612P3HIGHCVSS 7.5v5.0.0v5.1.0+16 more2015-08-24
CVE-2014-3612 [HIGH] CWE-287 CVE-2014-3612: The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Ap
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability
nvdosv
CVE-2026-49877P3HIGHCVSS 8.1fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49877 [HIGH] CWE-285 CVE-2026-49877: Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins.
This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade
nvd
CVE-2018-11775P3HIGHCVSS 7.4fixed in 5.15.62018-09-10
CVE-2018-11775 [HIGH] CWE-295 CVE-2018-11775: TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which coul
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
nvdosv
CVE-2026-54475P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-54475 [HIGH] CWE-862 CVE-2026-54475: Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's tem
nvd
CVE-2026-50734P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-50734 [HIGH] CWE-789 CVE-2026-50734: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotia
nvd
CVE-2026-49434P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49434 [HIGH] CWE-20 CVE-2026-49434: Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerServic
nvd
CVE-2026-53916P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-53916 [HIGH] CWE-789 CVE-2026-53916: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without limit, exhausting the JVM heap.
This issue affects Apache ActiveMQ: before 5.19.8,
nvd