Denial of Service Vulnerability in Apache Artemis and ActiveMQ Artemis
CVE-2026-57822
Currently unrated
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-57822?
A vulnerability exists in the processing of message-based management requests within Apache Artemis and ActiveMQ Artemis. An authenticated client with management permissions can exploit this issue by sending carefully crafted payloads. The malicious parameters can initiate Java deserialization, leading to excessive computational demands on the broker. This condition may result in prolonged processing times, effectively pinning the processing thread and causing a denial of service. To mitigate this vulnerability, users should upgrade to version 2.57.0, which resolves the underlying issue.
Affected Version(s)
Apache ActiveMQ Artemis 1.3.0 <= 2.44.0
Apache Artemis 2.50.0 <= 2.56.0