Search CVE reports


Toggle filters

1 – 10 of 59 results


CVE-2026-61487

Medium priority
Needs evaluation

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary composite...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-59878

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54475

Medium priority
Needs evaluation

Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53917

Medium priority
Needs evaluation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53916

Medium priority
Needs evaluation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-52760

Medium priority
Needs evaluation

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-50750

Medium priority
Needs evaluation

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-50734

Medium priority
Needs evaluation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49877

Medium priority
Needs evaluation

Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit those paths to...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49434

Medium priority
Needs evaluation

Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and searchFilter can...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages