Input Validation Flaw in Apache ActiveMQ Products by Apache
CVE-2026-59878

7.5HIGH

What is CVE-2026-59878?

An improper input validation vulnerability exists in Apache ActiveMQ products that allows remote unauthenticated attackers to leverage an exposed AMQP NIO connector. By sending malicious frame size values, attackers can trigger denial-of-service conditions that exhaust the NIO thread pool, making the service unavailable to legitimate connections. This issue primarily affects versions prior to 5.19.9 and early releases from 6.0.0 up to 6.2.8. Users are strongly advised to upgrade to newer versions 5.19.9, 6.2.8, or 6.3.0 to mitigate this vulnerability.

Affected Version(s)

Apache ActiveMQ 0 < 5.19.9

Apache ActiveMQ 6.0.0 < 6.2.8

Apache ActiveMQ All 0 < 5.19.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zx (Jace)
.