Improper Input Validation in Apache ActiveMQ Products by Apache
CVE-2026-49432

7.5HIGH

What is CVE-2026-49432?

An improper input validation vulnerability exists in Apache ActiveMQ that can be exploited by a remote, unauthenticated attacker. This vulnerability enables the attacker to cause denial-of-service (DoS) conditions by sending a negative content-length to an exposed STOMP connector. For connections using the NIO STOMP transport, attackers can continuously stream body bytes, leading to a potential out-of-memory (OOM) situation due to the command buffer exceeding its configured limits. In the case of blocking STOMP protocol, it forces abnormal exception handling, leading to the termination of the affected connection. Users should promptly upgrade to version 5.19.8 or 6.2.7 to mitigate this vulnerability.

Affected Version(s)

Apache ActiveMQ 0 < 5.19.8

Apache ActiveMQ 6.0.0 < 6.2.7

Apache ActiveMQ All 0 < 5.19.8

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Youngjoon Kim
.