Description

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7. Users are recommended to upgrade to version 6.2.7, which fixes the issue.

Severity (CVSS)

Base score7.5
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Provided byCISA-ADP

Weaknesses

  • — Denial of Service via Out of Memory
  • CWE-400 — CWE-400 Uncontrolled Resource Consumption

Affected products

VendorProductVersions
Apache Software FoundationApache ActiveMQ Broker5.19.7 to <5.19.8; 6.2.6 to <6.2.7
Apache Software FoundationApache ActiveMQ5.19.7 to <5.19.8; 6.2.6 to <6.2.7
Apache Software FoundationApache ActiveMQ All5.19.7 to <5.19.8; 6.2.6 to <6.2.7

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 01 Jul 2026 07:05 UTC.