Description
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.

An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker.
This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.

Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Memory allocation with an excessive size value, a CWE-770 and CWE-789 vulnerability, allows an unauthenticated network attacker to trigger a broker denial of service by sending a crafted WireFormatInfo frame during pre‑authentication. The broker does not validate the size field and attempts to allocate that amount of memory, causing an out‑of‑memory condition that crashes the broker. The direct impact is the loss of availability of the broker, interrupting messaging services for all connected clients.

Affected Systems

Apache ActiveMQ client and broker components from the Apache Software Foundation, including the 'Apache ActiveMQ All' bundle, are affected. Versions prior to 5.19.8 and versions 6.0.0 through 6.2.6 contain the vulnerability.

Risk and Exploitability

The vulnerability can be invoked by an attacker from any network location prior to authentication, making it widely exploitable. Although EPSS data is not available and the issue is not listed in the CISA KEV catalog, the nature of the flaw—pre‑authentication memory allocation—suggests a high impact on availability and a reasonable likelihood of exploitation. The CVSS score is 7.5, indicating significant severity, but the primary risk remains a broker crash rather than confidentiality or integrity compromise.

Generated by OpenCVE AI on July 1, 2026 at 12:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache ActiveMQ to version 5.19.8 or 6.2.7 or later, which contains the fix.
  • Restrict inbound traffic to the broker, allowing only trusted hosts or networks to connect, to reduce exposure before the patch can be applied.
  • Configure JVM or container memory limits and implement monitoring for OOM events, so that the broker can be restarted automatically or prevented from crashing due to excessive allocation.

Generated by OpenCVE AI on July 1, 2026 at 12:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq
Apache activemq All
Vendors & Products Apache
Apache activemq
Apache activemq All

Wed, 01 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770
References
Metrics threat_severity

None

threat_severity

Important


Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
Description Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Title Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
Weaknesses CWE-789
References

Subscriptions

Apache Activemq Activemq All
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-06-30T12:32:25.918Z

Reserved: 2026-06-05T17:01:29.414Z

Link: CVE-2026-50734

cve-icon Vulnrichment

Updated: 2026-06-30T11:06:17.570Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-30T09:53:03Z

Links: CVE-2026-50734 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T12:45:16Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling

  • CWE-789

    Memory Allocation with Excessive Size Value