πŸ” CVE Alert

CVE-2026-42253

MEDIUM 6.1

Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties

CVSS Score
6.1
EPSS Score
0.2%
EPSS Percentile
38th

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6. Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue.Β The MessageServlet has now been deprecated and disabled by default.

CWE CWE-79
Vendor apache software foundation
Product apache activemq
Published Jun 1, 2026
Last Updated Jun 3, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache activemq

Be the first to know when new medium vulnerabilities affecting apache software foundation apache activemq are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Apache Software Foundation / Apache ActiveMQ
0 < 5.19.7 6.0.0 < 6.2.6
Apache Software Foundation / Apache ActiveMQ Web
0 < 5.19.7 6.0.0 < 6.2.6

References

NVD β†— CVE.org β†— EPSS Data β†—
lists.apache.org: https://lists.apache.org/thread/j9vmlc410ht5f28fc98gx75jcbq62j00 openwall.com: http://www.openwall.com/lists/oss-security/2026/05/31/17

Credits

Vishal Shukla pyn3rd uname 4ra1n kikayli