Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-59878PATCHED
apache · activemq

Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS

Description

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.

Affected Products

VendorProductVersions
apacheactivemq0, 6.0.0, 0, 6.0.0, 0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheactivemq_allcve_cpe95%
apacheactivemq_amqpcve_cpe95%

References

  • https://lists.apache.org/thread/dnyx4d2oldshcj4lthso7b53y4bqmjvn(vendor-advisory)

Related News (4 articles)

Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits IBM (25 septembre 2026)
→ No new info (linked only)
Tier C
VulDB61d ago
CVE-2026-59878 | Apache ActiveMQ AMQP/ActiveMQ/ActiveMQ All up to 5.19.8/6.2.7 AMQP NIO Connector input validation
→ No new info (linked only)
Tier B
BSI Advisories61d ago
[NEU] [mittel] Apache ActiveMQ: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security62d ago
CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS0.00(Top 60%)
CISA KEV❌ No
Actively exploited❌ No
Patch available
5.19.96.2.8
CWECWE-20
PublishedJul 28, 2026
Last enriched61d ago
Trending Score38
Source articles4
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-71290
Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)
Trending: 45
CRITICALCVE-2026-55976
Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Trending: 33
CRITICALCVE-2026-49845
Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Trending: 27
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 20
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 19

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 28, 2026
Discovered by ZDM
Jul 28, 2026
Patch Available
Jul 28, 2026