Apache / Artemis
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation | HIGH | 8.2 | Sep 10, 2026 |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription | HIGH | 7.5 | Sep 10, 2026 |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers | CRITICAL | 9.1 | Sep 10, 2026 |
| CVE-2026-57822 | Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service | MEDIUM | 6.5 | Sep 10, 2026 |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment | CRITICAL | 9.8 | Sep 10, 2026 |
| CVE-2026-67593 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion | CRITICAL | 9.1 | Sep 10, 2026 |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service | MEDIUM | 6.5 | Sep 10, 2026 |
| CVE-2026-40914 | Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-type can be updated by STOMP protocol user without the createAddress per… | MEDIUM | 4.3 | May 28, 2026 |
| CVE-2026-32642 | Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission | LOW | 2.3 | Mar 24, 2026 |
| CVE-2026-27446 | Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation | CRITICAL | 9.3 | Mar 4, 2026 |
| CVE-2025-27391 | Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log | MEDIUM | 6.8 | Apr 9, 2025 |
| CVE-2025-27427 | Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission | LOW | 2.3 | Apr 1, 2025 |
| CVE-2023-50780 | Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans | HIGH | 7.7 | Oct 14, 2024 |
| CVE-2021-4040 | Broker: Malformed message can result in partial DoS (OOM) | MEDIUM | 5.3 | Aug 24, 2022 |
| CVE-2022-35278 | HTML Injection in ActiveMQ Artemis Web Console | MEDIUM | 6.1 | Aug 23, 2022 |
| CVE-2022-23913 | Apache ActiveMQ Artemis DoS | HIGH | 7.5 | Feb 4, 2022 |
| CVE-2021-26118 | Flaw in ActiveMQ Artemis OpenWire support | HIGH | 7.5 | Jan 27, 2021 |
| CVE-2021-26117 | ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind | HIGH | 8.1 | Jan 27, 2021 |
| CVE-2020-13932 | activemq: remote XSS in web console diagram plugin | MEDIUM | 6.5 | Jul 20, 2020 |
| CVE-2020-10727 | broker: resetUsers operation stores password in plain text | MEDIUM | 5.5 | Jun 26, 2020 |
| CVE-2017-12174 | artemis/hornetq: memory exhaustion via UDP and JGroups discovery | HIGH | 7.5 | Mar 7, 2018 |
| CVE-2016-4978 | Artemis: Deserialization of untrusted input vulnerability | HIGH | 7.2 | Sep 27, 2016 |
Showing 1 to 22 of 22 CVEs