Apache Activemq

Apache · 36 CVEs

CVE-2026-74761
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId

Sep 9, 2026

CVE-2026-59878
HIGH

Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to D…

Jul 28, 2026

CVE-2026-61487
MEDIUM

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations

Jul 28, 2026

CVE-2026-49434
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a…

Jun 30, 2026

CVE-2026-49432
HIGH

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service

Jun 30, 2026

CVE-2026-49877
HIGH

Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console

Jun 30, 2026

CVE-2026-50734
HIGH

Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during…

Jun 30, 2026

CVE-2026-50750
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-202…

Jun 30, 2026

CVE-2026-52760
MEDIUM

Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console

Jun 30, 2026

CVE-2026-53916
HIGH

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec

Jun 30, 2026

CVE-2026-53917
HIGH

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in Op…

Jun 30, 2026

CVE-2026-54475
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover

Jun 30, 2026

CVE-2026-42253
MEDIUM

Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties

Jun 1, 2026

CVE-2026-42588
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector

Jun 1, 2026

CVE-2026-45505
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass

Jun 1, 2026

CVE-2026-46605
MEDIUM

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal

Jun 1, 2026

CVE-2026-49157
HIGH

Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default

Jun 1, 2026

CVE-2026-49270
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (O…

Jun 1, 2026

CVE-2026-41044
HIGH

Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MB…

Apr 24, 2026

CVE-2026-41043
MEDIUM

Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues

Apr 24, 2026

CVE-2026-40466
HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery seco…

Apr 24, 2026

CVE-2026-39304
HIGH

Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 Key…

Apr 10, 2026

CVE-2026-40046
HIGH

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaini…

Apr 9, 2026

CVE-2026-33227
MEDIUM

Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Lim…

Apr 7, 2026

CVE-2026-34197
KEV HIGH

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Apr 7, 2026

Showing 1 to 25 of 36 CVEs