๐Ÿ” CVE Alert

CVE-2026-50734

UNKNOWN 0.0

Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

CWE CWE-789
Vendor apache software foundation
Product apache activemq client
Published Jun 30, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache activemq client

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache activemq client are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache ActiveMQ Client
0 < 5.19.8 6.0.0 < 6.2.7
Apache Software Foundation / Apache ActiveMQ
0 < 5.19.8 6.0.0 < 6.2.7
Apache Software Foundation / Apache ActiveMQ All
0 < 5.19.8 6.0.0 < 6.2.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/nxso951fnvf72qf9m475mpz4yf931xk0 openwall.com: http://www.openwall.com/lists/oss-security/2026/06/29/10

Credits

Andrej Tomci