PT-2026-53842 · Apache · Activemq
CVE-2026-50750
·
Published
2026-06-30
·
Updated
2026-07-06
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ Broker versions 5.19.7 through 5.19.7
Apache ActiveMQ Broker versions 6.2.6 through 6.2.6
Apache ActiveMQ versions 5.19.7 through 5.19.7
Apache ActiveMQ versions 6.2.6 through 6.2.6
Apache ActiveMQ All versions 5.19.7 through 5.19.7
Apache ActiveMQ All versions 6.2.6 through 6.2.6
Description
An unauthenticated attacker can trigger a Denial of Service (DoS) by causing an Out of Memory (OOM) condition, which leads to a broker crash. This occurs when repeated
BrokerInfo commands are sent without a corresponding ConnectionInfo. OOM refers to a state where the system lacks sufficient memory to perform required operations.Recommendations
Upgrade Apache ActiveMQ Broker to version 6.2.7.
Upgrade Apache ActiveMQ to version 6.2.7.
Upgrade Apache ActiveMQ All to version 6.2.7.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activemq