Description
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7. Users are recommended to upgrade to version 6.2.7, which fixes the issue.
Severity (CVSS)
| Base score | 7.5 |
|---|---|
| Severity | High |
| Version | CVSS 3.1 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Provided by | CISA-ADP |
Weaknesses
- — Denial of Service via Out of Memory
- CWE-400 — CWE-400 Uncontrolled Resource Consumption
Affected products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache ActiveMQ Broker | 5.19.7 to <5.19.8; 6.2.6 to <6.2.7 |
| Apache Software Foundation | Apache ActiveMQ | 5.19.7 to <5.19.8; 6.2.6 to <6.2.7 |
| Apache Software Foundation | Apache ActiveMQ All | 5.19.7 to <5.19.8; 6.2.6 to <6.2.7 |
References
- https://lists.apache.org/thread/nhkmbdym61yp6wwy0dny8w1p46sm87kr (vendor-advisory)
Generated from the official CVE List on 01 Jul 2026 07:05 UTC.