Search CVE reports


Toggle filters

1 – 10 of 48 results


CVE-2026-49270

Medium priority
Needs evaluation

Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-49157

Medium priority
Needs evaluation

Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-46605

Medium priority
Needs evaluation

Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45505

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42588

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42253

Medium priority
Needs evaluation

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41044

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-41043

Medium priority
Needs evaluation

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40466

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-39304

Medium priority
Needs evaluation

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This...

1 affected package

activemq

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages