Apache Software Foundation Apache Activemq Broker vulnerabilities
3 known vulnerabilities affecting apache_software_foundation/apache_activemq_broker.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2026-39304HIGHCVSS 7.5fixed in 5.19.4≥ 6.0.0, < 6.2.42026-04-10
CVE-2026-39304 [HIGH] CWE-400 CVE-2026-39304: Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker,
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ.
ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine
cvelistv5nvd
CVE-2026-34197HIGHCVSS 8.8PoCfixed in 5.19.4≥ 6.0.0, < 6.2.32026-04-07
CVE-2026-34197 [HIGH] CWE-20 CVE-2026-34197: Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability i
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), includi
cvelistv5nvd
CVE-2026-33227MEDIUMCVSS 4.3fixed in 5.19.3≥ 6.0.0, < 6.2.22026-04-07
CVE-2026-33227 [MEDIUM] CWE-22 CVE-2026-33227: Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Cli
Improper validation and restriction of a classpath path name vulnerability in
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ.
In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to t
cvelistv5nvd