CVE-2026-49432

Red Hat Security Advisory: Red Hat AMQ Broker 7.13.6 release and security update

Beschreibung

Eine Schwachstelle durch unsachgemäße Eingabevalidierung in Apache ActiveMQ, Apache ActiveMQ All und Apache ActiveMQ Stomp. Ein entfernter, nicht authentifizierter Peer, der einen offengelegten STOMP-Connector erreichen kann, kann eine Denial-of-Service-Behandlung auslösen, indem er eine negative Inhaltslänge sendet. Für den NIO-STOMP-Transport kann ein Angreifer kontinuierlich Body-Bytes streamen und den pro-Verbindung-Befehlspuffer über die konfigurierten Grenzen hinaus wachsen lassen, um einen Out-of-Memory-Fehler (OOM) zu verursachen. Für das blockierende STOMP-Protokoll wird stattdessen ein Fehler eine ungewöhnliche Transport-Ausnahmebehandlung für die betroffene Verbindung und deren Schließung erzwingen. Dieses Problem betrifft Apache ActiveMQ: vor 5.19.8, von 6.0.0 bis einschließlich 6.2.7; Apache ActiveMQ All: vor 5.19.8, von 6.0.0 bis einschließlich 6.2.7; Apache ActiveMQ Stomp: vor 5.19.8, von 6.0.0 bis einschließlich 6.2.7. Benutzer werden empfohlen, auf Version 6.2.7 oder 5.19.8 zu aktualisieren, die das Problem beheben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
54.0 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.8 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-09-10 23:22 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-02 18:43 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* versions up to (excluding) 5.19.8 *cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.2.7
    • Reference Type: Apache Software Foundation: https://lists.apache.org/thread/fsjb26605syqr8xks249h8gkp86t55d2 Types: Mailing List, Vendor Advisory
    • Reference Type: CVE: http://www.openwall.com/lists/oss-security/2026/06/29/7 Types: Third Party Advisory
  2. CVE Modified2026-06-30 12:16 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/06/29/7
  3. New CVE Received2026-06-30 11:16 UTC· security@apache.org
    • Affected: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp
    • Description: Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
    • CWE: CWE-20
    • Reference: https://lists.apache.org/thread/fsjb26605syqr8xks249h8gkp86t55d2

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Apache

    ActiveMQArtemis <2.57.0

  • apache

    qpid_proton-j0.35.0

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • axios

    axios1.0.0 – 1.15.2

  • beaugunderson

    ip-address10.1.1

  • bitnami

    activemq6.0.0

  • bitnami

    postgresql-jdbc-driver42.2.0

  • FasterXML

    Jackson2.18.6

  • FasterXML

    Jackson2.21.1

  • FasterXML

    Jackson3.1.0

  • IBM

    MQAppliance <10.0.0.5

  • IBM

    MQAppliance <9.4.0.26

  • IBM

    MQAppliance <9.4.5.3

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

Quellen & Referenzen

Verknüpfte CVEs

34 weitere CVEs anzeigen
IDCVE-2026-49432