Apache Software Foundation Apache Activemq vulnerabilities
28 known vulnerabilities affecting apache_software_foundation/apache_activemq.
Total CVEs
28
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
4
Severity breakdown
CRITICAL1HIGH18MEDIUM8LOW1
Vulnerabilities
Page 1 of 2
CVE-2023-46604P1CRITICALCVSS 9.8KEVPoCRansomware≥ 5.18.0, < 5.18.3≥ 5.17.0, < 5.17.6+2 more2023-10-27
CVE-2023-46604 [CRITICAL] CWE-502 CVE-2023-46604: The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability ma
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
i
nvd
CVE-2026-34197P1HIGHCVSS 8.8KEVPoCfixed in 5.19.7≥ 6.0.0, < 6.2.62026-04-07
CVE-2026-34197 [HIGH] CWE-20 CVE-2026-34197: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), includi
nvd
CVE-2018-8006P1MEDIUMCVSS 6.1ExploitedPoCv5.0.0 to 5.15.52018-10-10
CVE-2018-8006 [MEDIUM] CWE-79 CVE-2018-8006: An instance of a cross-site scripting vulnerability was identified to be present in the web based ad
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter.
nvd
CVE-2024-32114P1HIGHCVSS 8.8ExploitedPoC≥ 6.0.0, ≤ 6.1.12024-05-02
CVE-2024-32114 [HIGH] CWE-1188 CVE-2024-32114: In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolo
In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located).
It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purg
nvd
CVE-2022-41678P1HIGHCVSS 8.8PoCfixed in 5.16.6≥ 5.17.0, < 5.17.42023-11-28
CVE-2022-41678 [HIGH] CWE-287 CVE-2022-41678: Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.
In details, in ActiveMQ configurations, jetty allows
org.jolokia.http.AgentServlet to handler request to /api/jolokia
org.jolokia.http.HttpRequestHandler#handlePostRequest is able to
create JmxRequest through JSONObject. And calls to
org.jolokia.http.HttpRequ
nvd
CVE-2025-27533P3HIGHCVSS 7.5PoC≥ 6.0.0, < 6.1.6≥ 5.18.0, < 5.18.7+2 more2025-05-07
CVE-2025-27533 [HIGH] CWE-789 CVE-2025-27533: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ.
During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and be exploited to cause a denial of service (DoS) by depleting process memory, thereby affecting applications and services that rel
nvd
CVE-2026-41044P2HIGHCVSS 8.8fixed in 5.19.6≥ 6.0.0, < 6.2.52026-04-24
CVE-2026-41044 [HIGH] CWE-20 CVE-2026-41044: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All.
An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM tr
nvd
CVE-2025-66168P3HIGHCVSS 8.8≥ 6.0.0, < 6.2.42026-03-04
CVE-2025-66168 [HIGH] CWE-190 CVE-2025-66168: WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releas
WARNING:
Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases.
See the following for more details:
https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt
https://www.cve.org/CVERecord?id=CVE-2026-40046
Original Report:
Apache ActiveMQ does not properly validate the remaining len
nvd
CVE-2026-49157P3HIGHCVSS 8.8fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-49157 [HIGH] CWE-276 CVE-2026-49157: Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ:
Incorrect Default Permissions vulnerability in Apache ActiveMQ.
This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6.
The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jolokia operations which allowed executing broker management operations meant for admins such as addQueue
nvd
CVE-2026-42588P3HIGHCVSS 8.1fixed in 5.19.7≥ 6.0.0, < 6.2.62026-06-01
CVE-2026-42588 [HIGH] CWE-20 CVE-2026-42588: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache
nvd
CVE-2021-26117P3HIGHCVSS 7.5≥ Apache ActiveMQ Artemis, < 2.16.0≥ Apache ActiveMQ, < 5.16.12021-01-27
CVE-2021-26117 [HIGH] CWE-287 CVE-2021-26117: The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server
The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users password in error, resulting in no check on the password.
nvd
CVE-2026-49877P3HIGHCVSS 8.1fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49877 [HIGH] CWE-285 CVE-2026-49877: Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console
Improper Authorization vulnerability in Apache ActiveMQ.
An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to only admins.
This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade
nvd
CVE-2018-11775P3HIGHCVSS 7.4v5.0.0 - 5.15.52018-09-10
CVE-2018-11775 [HIGH] CWE-295 CVE-2018-11775: TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which coul
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
nvd
CVE-2026-54475P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-54475 [HIGH] CWE-862 CVE-2026-54475: Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's tem
nvd
CVE-2026-50734P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-50734 [HIGH] CWE-789 CVE-2026-50734: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotia
nvd
CVE-2026-49434P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49434 [HIGH] CWE-20 CVE-2026-49434: Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ
Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can instantiate denied transports inside the broker JVM. This can be used to fetch an attacker URL and spawn a second BrokerServic
nvd
CVE-2026-53916P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-53916 [HIGH] CWE-789 CVE-2026-53916: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without limit, exhausting the JVM heap.
This issue affects Apache ActiveMQ: before 5.19.8,
nvd
CVE-2026-53917P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-53917 [HIGH] CWE-789 CVE-2026-53917: Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, A
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker.
An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are unmarshaled without size validation which
nvd
CVE-2026-39304P3HIGHCVSS 7.5fixed in 5.19.4≥ 6.0.0, < 6.2.42026-04-10
CVE-2026-39304 [HIGH] CWE-400 CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker,
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine
nvd
CVE-2026-49432P3HIGHCVSS 7.5fixed in 5.19.8≥ 6.0.0, < 6.2.72026-06-30
CVE-2026-49432 [HIGH] CWE-20 CVE-2026-49432: Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Sto
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection c
nvd
1 / 2Next →