Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Apache ActiveMQ — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Apache ActiveMQ, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Apache ActiveMQ, a popular open-source message broker. It collects a diverse range of flaws, including authentication bypasses, denial-of-service issues, and information disclosure defects, covering advisories published over the past decade. Readers can use this repository to track the vendor's security notices, understand the specific weakness classes impacting the product, and review its complete vulnerability history.

Vendor: Apache Software Foundation

CVE ID Title CVSS Severity Published
CVE-2026-49432 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service CWE-20 - - 2026-06-30
CVE-2026-49877 Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console CWE-285 - - 2026-06-30
CVE-2026-52760 Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console CWE-79 - - 2026-06-30
CVE-2026-53916 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec CWE-789 - - 2026-06-30
CVE-2026-53917 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling CWE-789 - - 2026-06-30
CVE-2026-42253 Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties CWE-79 - - 2026-06-01
CVE-2026-49157 Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default CWE-276 - - 2026-06-01
CVE-2026-41044 Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia CWE-20 7.2AI High AI 2026-04-24
CVE-2026-41043 Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues CWE-79 5.4AI Medium AI 2026-04-24
CVE-2026-40046 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated CWE-190 9.8AI Critical AI 2026-04-09
CVE-2025-66168 Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated CWE-190 5.4 Medium 2026-03-04
CVE-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation CWE-789 7.5AI High AI 2025-05-07
CVE-2024-32114 Apache ActiveMQ: Jolokia and REST API were not secured with default configuration CWE-1188 8.5 High 2024-05-02
CVE-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE CWE-287 8.8 - 2023-11-28
CVE-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack CWE-502 10.0 Critical 2023-10-27
CVE-2020-13947 Apache ActiveMQ 跨站脚本漏洞 6.1 - 2021-02-08
CVE-2021-26117 ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind CWE-287 7.5 - 2021-01-27
CVE-2020-11998 Apache ActiveMQ 代码注入漏洞 8.1 - 2020-09-10
CVE-2020-13920 Apache ActiveMQ effect 授权问题漏洞 5.9 - 2020-09-10
CVE-2020-1941 Apache ActiveMQ 跨站脚本漏洞 6.1 - 2020-05-14
CVE-2019-0222 Apache ActiveMQ 代码注入漏洞 7.5 - 2019-03-28
CVE-2018-8006 Apache ActiveMQ 跨站脚本漏洞 6.1 - 2018-10-10
CVE-2018-11775 Apache ActiveMQ Client 信任管理问题漏洞 7.4 - 2018-09-10
CVE-2017-15709 ActiveMQ 信息泄露漏洞 5.9 - 2018-02-13
CVE-2016-6810 Apache ActiveMQ 跨站脚本漏洞 6.1 - 2018-01-10

All 25 known CVE vulnerabilities affecting Apache ActiveMQ with full Chinese analysis, references, and POCs where available.