PT-2026-53841 · Apache · Activemq+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ Client versions prior to 5.19.8
Apache ActiveMQ Client versions 6.0.0 through 6.2.6
Apache ActiveMQ versions prior to 5.19.8
Apache ActiveMQ versions 6.0.0 through 6.2.6
Apache ActiveMQ All versions prior to 5.19.8
Apache ActiveMQ All versions 6.0.0 through 6.2.6
Description
An unauthenticated network attacker can cause a broker Denial of Service (DoS) by sending a crafted WireFormatInfo frame containing a malicious large size value. Because this value is not validated, the broker attempts a memory allocation during pre-authentication negotiation, which can trigger an Out of Memory (OOM) condition and crash the broker.
Recommendations
Upgrade Apache ActiveMQ Client versions prior to 5.19.8 to version 5.19.8.
Upgrade Apache ActiveMQ Client versions 6.0.0 through 6.2.6 to version 6.2.7.
Upgrade Apache ActiveMQ versions prior to 5.19.8 to version 5.19.8.
Upgrade Apache ActiveMQ versions 6.0.0 through 6.2.6 to version 6.2.7.
Upgrade Apache ActiveMQ All versions prior to 5.19.8 to version 5.19.8.
Upgrade Apache ActiveMQ All versions 6.0.0 through 6.2.6 to version 6.2.7.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activemq
Activemq Client