PT-2026-53845 · Apache · Activemq+2

·

CVE-2026-53917

·

Published

2026-06-30

·

Updated

2026-07-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ versions prior to 5.19.8 Apache ActiveMQ versions 6.0.0 through 6.2.6 Apache ActiveMQ All versions prior to 5.19.8 Apache ActiveMQ All versions 6.0.0 through 6.2.6 Apache ActiveMQ Client versions prior to 5.19.8 Apache ActiveMQ Client versions 6.0.0 through 6.2.6 Apache ActiveMQ Broker versions prior to 5.19.8 Apache ActiveMQ Broker versions 6.0.0 through 6.2.6
Description An authenticated user can trigger a Denial of Service (DoS) by sending a specially crafted OpenWire Message containing an excessive encoded size value for the map. Because OpenWire message property maps are unmarshaled without proper size validation, this can lead to Out of Memory (OOM) conditions, causing the broker to crash.
Recommendations Upgrade Apache ActiveMQ to version 5.19.8 or 6.2.7. Upgrade Apache ActiveMQ All to version 5.19.8 or 6.2.7. Upgrade Apache ActiveMQ Client to version 5.19.8 or 6.2.7. Upgrade Apache ActiveMQ Broker to version 5.19.8 or 6.2.7.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-53917
CVE-2026-53917
OESA-2026-2921
OESA-2026-2922
OESA-2026-2923

Affected Products

Activemq
Activemq Broker
Activemq Client