PT-2026-65463 · Apache · Activemq Amqp+1

CVE-2026-59878

·

Published

2026-07-28

·

Updated

2026-08-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ AMQP versions prior to 5.19.9 Apache ActiveMQ AMQP versions 6.0.0 through 6.2.7 Apache ActiveMQ versions prior to 5.19.9 Apache ActiveMQ versions 6.0.0 through 6.2.7 Apache ActiveMQ All versions prior to 5.19.9 Apache ActiveMQ All versions 6.0.0 through 6.2.7
Description Improper input validation in the AMQP NIO connector allows a remote unauthenticated peer to trigger a denial-of-service condition. By sending a specific frame size value, an attacker can cause NIO threads to terminate. If performed rapidly, this leads to the exhaustion of the NIO thread pool, preventing other connections from accessing the service.
Recommendations Upgrade Apache ActiveMQ AMQP to version 5.19.9, 6.2.8, or 6.3.0. Upgrade Apache ActiveMQ to version 5.19.9, 6.2.8, or 6.3.0. Upgrade Apache ActiveMQ All to version 5.19.9, 6.2.8, or 6.3.0.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-ACTIVEMQ-2026-59878
CVE-2026-59878
OESA-2026-3264
OESA-2026-3265
OESA-2026-3266
OESA-2026-3267

Affected Products

Activemq
Activemq Amqp