Unsafe Reflection Vulnerability in Apache ActiveMQ Artemis by Red Hat
CVE-2026-101292
What is CVE-2026-101292?
Apache ActiveMQ Artemis prior to version 2.34.0 is affected by an unsafe reflection vulnerability that arises in the FederationStreamConnectMessage.getFederationPolicy() method. This method retrieves a specified class name directly from the CORE protocol wire buffer without proper type validation. An authenticated peer in the federation can transmit a malformed FEDERATION_DOWNSTREAM_CONNECT packet, manipulating the class name to force the broker to load and instantiate any classes that are accessible to the Artemis module classloader. This exploitation could lead to serious consequences, including denial of service through system-property poisoning, out-of-memory errors caused by excessive class loading, or manipulation of the broker's state.