Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5423 articles · 221078 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-50734PATCHED
apache · activemq

Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation

Description

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

Affected Products

VendorProductVersions
apacheactivemq0, 6.0.0, 0, 6.0.0, 0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheapache activemqmitre_affected90%
apacheapache activemq allmitre_affected90%
apacheactivemqcert_advisory90%
ibmqradar siemcert_advisory90%
oraclecommunicationscert_advisory90%

References

  • https://lists.apache.org/thread/nxso951fnvf72qf9m475mpz4yf931xk0(vendor-advisory)

Related News (8 articles)

Tier B
CERT-FR4d ago
Multiples vulnérabilités dans les produits IBM (18 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories6d ago
[NEU] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR25d ago
Multiples vulnérabilités dans les produits IBM (28 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories26d ago
[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR46d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories84d ago
[NEU] [mittel] Apache ActiveMQ: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB84d ago
CVE-2026-50734 | Apache ActiveMQ up to 5.19.7/6.2.6 OpenWire denial of service
→ No new info (linked only)
Tier C
oss-security85d ago
CVE-2026-50734: Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.19.86.2.7
CWECWE-789
PublishedJun 30, 2026
Last enriched84d ago
Trending Score33
Source articles8
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 42
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 42
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 37
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 34

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 30, 2026
Discovered by ZDM
Jun 30, 2026
Patch Available
Jun 30, 2026