PT-2026-31892 · Apache+1 · Apache Activemq Client+3
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ Client versions before 5.19.4, from 6.0.0 through 6.2.3
Apache ActiveMQ Broker versions before 5.19.4, from 6.0.0 through 6.2.3
Apache ActiveMQ versions before 5.19.4, from 6.0.0 through 6.2.3
Description
A denial of service issue exists due to out-of-memory conditions in Apache ActiveMQ Client, Apache ActiveMQ Broker, and Apache ActiveMQ. The vulnerability occurs because NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates initiated by clients, leading to rapid updates that exhaust the broker's memory in the SSL engine, resulting in a denial of service. TLS versions prior to TLSv1.3 are not vulnerable to out-of-memory conditions, but may cause connection hangs.
Recommendations
Upgrade to version 6.2.4 or 5.19.5 to resolve the issue.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Activemq
Apache Activemq Broker
Apache Activemq Client
Red Os