Apache Software Foundation Apache Activemq All vulnerabilities
5 known vulnerabilities affecting apache_software_foundation/apache_activemq_all.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-39304HIGHCVSS 7.5fixed in 5.19.4≥ 6.0.0, < 6.2.42026-04-10
CVE-2026-39304 [HIGH] CWE-400 CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker,
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine
cvelistv5nvd
CVE-2026-40046MEDIUMCVSS 5.4≥ 6.0.0, < 6.2.42026-04-09
CVE-2026-40046 [MEDIUM] CWE-190 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT.
The fix for "CVE-2025-66168: MQTT co
cvelistv5
CVE-2026-34197HIGHCVSS 8.8PoCfixed in 5.19.4≥ 6.0.0, < 6.2.32026-04-07
CVE-2026-34197 [HIGH] CWE-20 CVE-2026-34197: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), includi
cvelistv5nvd
CVE-2026-33227MEDIUMCVSS 4.3fixed in 5.19.3≥ 6.0.0, < 6.2.22026-04-07
CVE-2026-33227 [MEDIUM] CWE-22 CVE-2026-33227: Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Cli
Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.
In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to t
cvelistv5nvd
CVE-2025-66168HIGHCVSS 8.8≥ 6.0.0, < 6.2.42026-03-04
CVE-2025-66168 [MEDIUM] CWE-190 CVE-2025-66168: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow
Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to un
nvd