当代理(Broker)处理由具备 权限、有权通过消息进行管理的认证消息客户端发送的基于消息的管理请求时,其参数处理逻辑可能会触发对某些代理本身不会实际使用的方法参数进行 Java 反序列化。允许反序列化的类型范围允许攻击者构造特定载荷,从而引发过度计算并占住处理线程,导致服务拒绝(Denial of Service, DoS)。 该问题影响以下版本: Apache Artemis:2.50.0 至 2.56.0 Apache ActiveMQ Artemis:1.3.0 至 2.44.0 建议用户升级至 2.57.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Artemis | 2.50.0 ~ 2.56.0 | - |
|
| Apache Software Foundation | Apache ActiveMQ Artemis | 1.3.0 ~ 2.44.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84939 | Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path trave | |
| CVE-2026-49362 | Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A | |
| CVE-2026-49363 | Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE | |
| CVE-2026-49364 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth | |
| CVE-2026-57967 | Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r | |
| CVE-2026-67593 | Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth | |
| CVE-2026-75880 | Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to |
No comments yet