Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-59878PATCHED
apache · activemq

Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS

Description

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.

Affected Products

VendorProductVersions
apacheactivemq0, 6.0.0, 0, 6.0.0, 0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheactivemq_allcve_cpe95%
apacheactivemq_amqpcve_cpe95%

References

  • https://lists.apache.org/thread/dnyx4d2oldshcj4lthso7b53y4bqmjvn(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (25 septembre 2026)
→ No new info (linked only)
Tier C
VulDB61d ago
CVE-2026-59878 | Apache ActiveMQ AMQP/ActiveMQ/ActiveMQ All up to 5.19.8/6.2.7 AMQP NIO Connector input validation
→ No new info (linked only)
Tier B
BSI Advisories61d ago
[NEU] [mittel] Apache ActiveMQ: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security62d ago
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS0.00(Top 60%)
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.19.96.2.8
CWECWE-20
PublishedJul 28, 2026
Last enriched61d ago
Trending Score39
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Trending: 45
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-49845
Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Trending: 27
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 21
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 19

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 28, 2026