Denial of Service Vulnerability in Apache ActiveMQ Broker by Apache
CVE-2026-50750
7.5HIGH
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 30 June 2026
What is CVE-2026-50750?
An unauthenticated attacker can exploit a Denial of Service vulnerability within Apache ActiveMQ Broker, causing an Out of Memory condition. This is achieved by sending repeated BrokerInfo commands without establishing a ConnectionInfo, eventually leading to a crash of the broker due to resource exhaustion. Users are strongly advised to update to version 6.2.7 or later to mitigate this issue.
Affected Version(s)
Apache ActiveMQ 5.19.7 < 5.19.8
Apache ActiveMQ 6.2.6 < 6.2.7
Apache ActiveMQ All 5.19.7 < 5.19.8