Apache / Activemq
75 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-74761 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId | HIGH | 7.5 | Sep 9, 2026 |
| CVE-2026-59878 | Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS | HIGH | 7.5 | Jul 28, 2026 |
| CVE-2026-61487 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations | MEDIUM | 6.5 | Jul 28, 2026 |
| CVE-2026-49434 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker | HIGH | 7.6 | Jun 30, 2026 |
| CVE-2026-49432 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-49877 | Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console | HIGH | 8.1 | Jun 30, 2026 |
| CVE-2026-50734 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-50750 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270 | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-52760 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console | MEDIUM | 6.1 | Jun 30, 2026 |
| CVE-2026-53916 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-53917 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling | HIGH | 7.5 | Jun 30, 2026 |
| CVE-2026-54475 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover | HIGH | 8.2 | Jun 30, 2026 |
| CVE-2026-42253 | Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties | MEDIUM | 6.1 | Jun 1, 2026 |
| CVE-2026-42588 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector | HIGH | 8.1 | Jun 1, 2026 |
| CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass | HIGH | 8.8 | Jun 1, 2026 |
| CVE-2026-46605 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal | MEDIUM | 6.5 | Jun 1, 2026 |
| CVE-2026-49157 | Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default | HIGH | 8.8 | Jun 1, 2026 |
| CVE-2026-49270 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire) | HIGH | 7.5 | Jun 1, 2026 |
| CVE-2026-41044 | Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia | HIGH | 8.8 | Apr 24, 2026 |
| CVE-2026-41043 | Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues | MEDIUM | 6.5 | Apr 24, 2026 |
| CVE-2026-40466 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI | HIGH | 8.8 | Apr 24, 2026 |
| CVE-2026-39304 | Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via… | HIGH | 7.5 | Apr 10, 2026 |
| CVE-2026-33227 | Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Cl… | MEDIUM | 4.3 | Apr 7, 2026 |
| CVE-2026-34197 KEV | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans | HIGH | 8.8 | Apr 7, 2026 |
| CVE-2025-66168 | Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated | HIGH | 8.8 | Mar 4, 2026 |
Showing 1 to 25 of 75 CVEs