Apache Software Foundation Apache Artemis vulnerabilities
8 known vulnerabilities affecting apache_software_foundation/apache_artemis.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-57967P2CRITICALCVSS 9.8≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-57967 [CRITICAL] CWE-306 CVE-2026-57967: An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an exi
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.
nvd
CVE-2026-49364P3CRITICALCVSS 9.1≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-49364 [CRITICAL] CWE-306 CVE-2026-49364: An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrativ
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes the
nvd
CVE-2026-67593P3CRITICALCVSS 9.1≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-67593 [CRITICAL] CWE-306 CVE-2026-67593: A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a qu
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recomm
nvd
CVE-2026-49363P3HIGHCVSS 7.5≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-49363 [HIGH] CWE-306 CVE-2026-49363: An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node detai
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes th
nvd
CVE-2026-49362P3HIGHCVSS 7.5≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-49362 [HIGH] CWE-306 CVE-2026-49362: An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leadin
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which
nvd
CVE-2026-57822P3MEDIUMCVSS 6.5≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-57822 [MEDIUM] CWE-502 CVE-2026-57822: When the broker is processing message-based management requests, sent by an authenticated messaging
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload
nvd
CVE-2026-75880P4MEDIUMCVSS 6.5≥ 2.50.0, ≤ 2.56.02026-09-10
CVE-2026-75880 [MEDIUM] CWE-1333 CVE-2026-75880: An authenticated client could attach a consumer with a selector containing crafted wildcard usage th
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0
nvd
CVE-2026-32642P4MEDIUMCVSS 4.3≥ 2.50.0, ≤ 2.52.02026-03-24
CVE-2026-32642 [MEDIUM] CWE-863 CVE-2026-32642: Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists wh
Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the "createDurableQueue" permission but does not have the "createAddress" permi
nvd