Memory Allocation Vulnerability in Apache ActiveMQ Products
CVE-2026-50734
7.5HIGH
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-50734?
A memory allocation vulnerability exists in Apache ActiveMQ products due to improper validation of size values in the WireFormatInfo frame. An unauthenticated attacker can exploit this vulnerability by sending a crafted frame, leading to a denial of service condition. This results in the broker attempting excessive memory allocation during the pre-authentication negotiation process, potentially causing an out-of-memory (OOM) condition and subsequent crash. Users are advised to upgrade to versions 6.2.7 or 5.19.8 to mitigate this risk.
Affected Version(s)
Apache ActiveMQ 0 < 5.19.8
Apache ActiveMQ 6.0.0 < 6.2.7
Apache ActiveMQ All 0 < 5.19.8