Unsafe Reflection Vulnerability in Apache ActiveMQ Artemis by Red Hat
CVE-2026-101292

8.2HIGH

What is CVE-2026-101292?

Apache ActiveMQ Artemis prior to version 2.34.0 is affected by an unsafe reflection vulnerability that arises in the FederationStreamConnectMessage.getFederationPolicy() method. This method retrieves a specified class name directly from the CORE protocol wire buffer without proper type validation. An authenticated peer in the federation can transmit a malformed FEDERATION_DOWNSTREAM_CONNECT packet, manipulating the class name to force the broker to load and instantiate any classes that are accessible to the Artemis module classloader. This exploitation could lead to serious consequences, including denial of service through system-property poisoning, out-of-memory errors caused by excessive class loading, or manipulation of the broker's state.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.