Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-57822— Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service

Quick assessment

Affected
Apache Software Foundation Apache Artemis
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当代理(Broker)处理由具备 权限、有权通过消息进行管理的认证消息客户端发送的基于消息的管理请求时,其参数处理逻辑可能会触发对某些代理本身不会实际使用的方法参数进行 Java 反序列化。允许反序列化的类型范围允许攻击者构造特定载荷,从而引发过度计算并占住处理线程,导致服务拒绝(Denial of Service, DoS)。 该问题影响以下版本: Apache Artemis:2.50.0 至 2.56.0 Apache ActiveMQ Artemis:1.3.0 至 2.44.0 建议用户升级至 2.57.

AI Predicted 7.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-57822

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Artemis 2.50.0 ~ 2.56.0 -
Apache Software Foundation Apache ActiveMQ Artemis 1.3.0 ~ 2.44.0 -

II. Public POCs for CVE-2026-57822

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-57822

登录查看更多情报信息。

Mailing List Discussions for CVE-2026-57822 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-10 · 11 CVEs total

CVE-2026-80354 Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secr
CVE-2026-80351 Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
CVE-2026-80352 Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author appl
CVE-2026-84939 Apache FreeMarker, Apache FreeMarker: A malformed locale may be exploitable for path trave
CVE-2026-49362 Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler A
CVE-2026-49363 Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE
CVE-2026-49364 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Auth
CVE-2026-57967 Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session r
CVE-2026-67593 Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-auth
CVE-2026-75880 Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to

IV. Related Vulnerabilities

V. Comments for CVE-2026-57822

No comments yet


Leave a comment