PT-2026-99872 · Apache · Activemq Artemis

CVE-2026-101292

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Apache ActiveMQ Artemis versions prior to 2.34.0
Description An unsafe reflection issue exists in the FederationStreamConnectMessage.getFederationPolicy() function. The system calls Class.forName(clazz).getConstructor().newInstance() using a clazz value read directly from the CORE protocol wire buffer without proper type validation. An authenticated federation peer can send a FEDERATION DOWNSTREAM CONNECT packet containing a crafted class name, forcing the broker to load and instantiate arbitrary classes available to the Artemis module classloader. This process executes static initializers (<clinit>) and no-argument constructors (<init>()) as side effects, which can lead to denial of service through system-property poisoning, out-of-memory conditions during classloading, or manipulation of the broker state.
Recommendations Update to version 2.34.0 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101292

Affected Products

Activemq Artemis