Apache ActiveMQ是Apache基金会的一款消息队列中间件。 Apache ActiveMQ存在资源管理错误漏洞,该漏洞源于内存分配时存在过大的尺寸值问题,OpenWire消息属性映射在反序列化时未进行大小验证,可能导致已认证用户通过发送特制的OpenWire消息(其中包含map的编码尺寸值过大)触发OOM并使代理崩溃,造成拒绝服务。以下版本受到影响:Apache ActiveMQ 5.19.8之前版本和6.0.0至6.2.7之前版本;Apache ActiveMQ All 5.19.8之前版
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected | ||
| Apache Software Foundation | Apache ActiveMQ All | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected | ||
| Apache Software Foundation | Apache ActiveMQ Broker | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected | ||
| Apache Software Foundation | Apache ActiveMQ Client | < 5.19.8 |
affected |
6.0.0< 6.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache ActiveMQ | 0 ~ 5.19.8 | - |
|
| Apache Software Foundation | Apache ActiveMQ All | 0 ~ 5.19.8 | - |
|
| Apache Software Foundation | Apache ActiveMQ Client | 0 ~ 5.19.8 | - |
|
| Apache Software Foundation | Apache ActiveMQ Broker | 0 ~ 5.19.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54475 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination owners | |
| CVE-2026-53916 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in ST | |
| CVE-2026-52760 | Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ | |
| CVE-2026-50750 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-50734 | Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire | |
| CVE-2026-49877 | Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console | |
| CVE-2026-49432 | Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length | |
| CVE-2026-49434 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instant | |
| CVE-2025-53648 | Apache Gravitino: SQL misconfiguration can access or truncate files |
No comments yet