PT-2026-99872 · Apache · Activemq Artemis
CVE-2026-101292
·
Published
2026-09-28
·
Updated
2026-09-29
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Apache ActiveMQ Artemis versions prior to 2.34.0
Description
An unsafe reflection issue exists in the
FederationStreamConnectMessage.getFederationPolicy() function. The system calls Class.forName(clazz).getConstructor().newInstance() using a clazz value read directly from the CORE protocol wire buffer without proper type validation. An authenticated federation peer can send a FEDERATION DOWNSTREAM CONNECT packet containing a crafted class name, forcing the broker to load and instantiate arbitrary classes available to the Artemis module classloader. This process executes static initializers (<clinit>) and no-argument constructors (<init>()) as side effects, which can lead to denial of service through system-property poisoning, out-of-memory conditions during classloading, or manipulation of the broker state.Recommendations
Update to version 2.34.0 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Activemq Artemis