PT-2026-53844 · Apache · Activemq

·

CVE-2026-53916

·

Published

2026-06-30

·

Updated

2026-07-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.19.8 Apache ActiveMQ versions 6.0.0 through 6.2.6 Apache ActiveMQ All versions prior to 5.19.8 Apache ActiveMQ All versions 6.0.0 through 6.2.6 Apache ActiveMQ Stomp versions prior to 5.19.8 Apache ActiveMQ Stomp versions 6.0.0 through 6.2.6
Description An unauthenticated client can exhaust the JVM heap by opening a STOMP NIO connection and sending header bytes that never terminate, causing the broker to buffer them without limit.
Recommendations Upgrade Apache ActiveMQ to version 5.19.8 or 6.2.7. Upgrade Apache ActiveMQ All to version 5.19.8 or 6.2.7. Upgrade Apache ActiveMQ Stomp to version 5.19.8 or 6.2.7.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-53916
CVE-2026-53916
OESA-2026-2921
OESA-2026-2922
OESA-2026-2923

Affected Products

Activemq