cbcvebase.

Apache Activemq vulnerabilities

72 known vulnerabilities affecting apache/activemq.

Total CVEs
72
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
6
Severity breakdown
CRITICAL13HIGH29MEDIUM27LOW3

Vulnerabilities

Page 3 of 4
CVE-2026-53917P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-53917 [HIGH] CWE-789 CVE-2026-53917: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are unmarshaled without size validation which
nvd
CVE-2026-39304P3HIGHCVSS 7.5fixed in 5.19.4≥ 6.0.0, < 6.2.42026-04-10
CVE-2026-39304 [HIGH] CWE-400 CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine
nvd
CVE-2014-3576P3HIGHCVSS 7.5≤ 5.10.02015-08-14
CVE-2014-3576 [HIGH] CWE-264 CVE-2014-3576: The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11 The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
nvdosv
CVE-2026-49432P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49432 [HIGH] CWE-20 CVE-2026-49432: Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Sto Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection c
nvd
CVE-2019-0222P3HIGHCVSS 7.5≥ 5.0.0, ≤ 5.15.82019-03-28
CVE-2019-0222 [HIGH] CVE-2019-0222: In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
nvdosv
CVE-2026-50750P3HIGHCVSS 7.5v5.19.7v6.2.62026-06-30
CVE-2026-50750 [HIGH] CVE-2026-50750: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broke
nvd
CVE-2019-0201P3MEDIUMCVSS 5.9v5.15.92019-05-23
CVE-2019-0201 [MEDIUM] CWE-862 CVE-2019-0201: An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s g An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is use
nvd
CVE-2019-10241P3MEDIUMCVSS 6.1v5.15.92019-04-22
CVE-2019-10241 [MEDIUM] CWE-79 CVE-2019-10241: In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vul In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
nvd
CVE-2026-41043P3MEDIUMCVSS 6.5fixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-41043 [MEDIUM] CWE-79 CVE-2026-41043: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apach Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field. This issue affec
nvd
CVE-2026-49270P3MEDIUMCVSS 5.9fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-49270 [MEDIUM] CWE-1230 CVE-2026-49270: Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache A Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthenticated attacker who can receive a list of all durable topic subscriptions in the broker, including cli
nvd
CVE-2020-13920P3MEDIUMCVSS 5.9fixed in 5.15.122020-09-10
CVE-2020-13920 [MEDIUM] CWE-306 CVE-2020-13920: Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the se Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively bec
nvdosv
CVE-2016-0734P4MEDIUMCVSS 6.1v5.0.0v5.1.0+25 more2016-04-07
CVE-2016-0734 [MEDIUM] CWE-254 CVE-2016-0734: The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-O The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element.
nvd
CVE-2013-3060P4MEDIUMCVSS 6.4≤ 5.7.0v4.0+16 more2013-04-21
CVE-2013-3060 [MEDIUM] CWE-287 CVE-2013-3060: The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests.
nvd
CVE-2016-6810P4MEDIUMCVSS 6.1≥ 5.0.0, < 5.14.22018-01-10
CVE-2016-6810 [MEDIUM] CWE-79 CVE-2016-6810: In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identi In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.
nvdosv
CVE-2012-5784P4MEDIUMCVSS 5.8≤ 5.7.02012-11-04
CVE-2012-5784 [MEDIUM] CWE-20 CVE-2012-5784: Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional I Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allo
nvd
CVE-2015-6524P4MEDIUMCVSS 5.0v5.0.0v5.1.0+16 more2015-08-24
CVE-2015-6524 [MEDIUM] CVE-2015-6524: The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Ap The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
nvdosv
CVE-2020-1941P4MEDIUMCVSS 6.1≥ 5.0.0, ≤ 5.15.112020-05-14
CVE-2020-1941 [MEDIUM] CWE-79 CVE-2020-1941: In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
nvdosv
CVE-2016-0782P4MEDIUMCVSS 5.4v5.1.0v5.2.0+26 more2016-08-05
CVE-2016-0782 [MEDIUM] CWE-79 CVE-2016-0782: The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13. The administration web console in Apache ActiveMQ 5.x before 5.11.4, 5.12.x before 5.12.3, and 5.13.x before 5.13.2 allows remote authenticated users to conduct cross-site scripting (XSS) attacks and consequently obtain sensitive information from a Java memory dump via vectors related to creating a queue.
nvdosv
CVE-2026-42253P4MEDIUMCVSS 6.1fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-42253 [MEDIUM] CWE-79 CVE-2026-42253: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them
nvd
CVE-2026-52760P4MEDIUMCVSS 6.1fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-52760 [MEDIUM] CWE-79 CVE-2026-52760: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly without sanitization. This allows an authenticated producer to send a message with a JMS message ID that has been crafted to contain HTML/
nvd
Apache Activemq vulnerabilities | cvebase