PT-2026-53838 · Apache · Activemq
Youngjoon Kim
·
Published
2026-06-30
·
Updated
2026-06-30
·
CVE-2026-49432
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ versions prior to 5.19.8
Apache ActiveMQ versions 6.0.0 through 6.2.6
Apache ActiveMQ All versions prior to 5.19.8
Apache ActiveMQ All versions 6.0.0 through 6.2.6
Apache ActiveMQ Stomp versions prior to 5.19.8
Apache ActiveMQ Stomp versions 6.0.0 through 6.2.6
Description
Improper input validation in the STOMP connector allows a remote unauthenticated peer to trigger a denial-of-service. By sending a negative
content-length, an attacker can cause different failure modes depending on the transport used. In the NIO STOMP transport, the attacker can continuously stream body bytes, causing the per-connection command buffer to exceed configured limits and lead to an Out of Memory (OOM) condition. In the blocking STOMP protocol, the error triggers abnormal transport exception handling, resulting in the closure of the affected connection.Recommendations
Upgrade Apache ActiveMQ to version 5.19.8 or 6.2.7.
Upgrade Apache ActiveMQ All to version 5.19.8 or 6.2.7.
Upgrade Apache ActiveMQ Stomp to version 5.19.8 or 6.2.7.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activemq