Impact
The flaw resides in the processing of message‑based management requests. When a client authenticated with MANAGE permission sends a specially crafted parameter, the broker deserializes the value even though it is not needed for execution. This unintended deserialization can trigger excessive computation and lock the processing thread, causing denial of service to the broker for legitimate users. The vulnerability does not provide remote code execution or compromise confidentiality; it solely disrupts service availability for those who possess the required permissions.
Affected Systems
Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.3.0 through 2.44.0 are affected. The fix is included in Apache Artemis 2.57.0; ActiveMQ Artemis can be updated to a release that incorporates this Artemis 2.57.0 patch.
Risk and Exploitability
The moderate severity. The EPSS score of <1% denotes a very low likelihood of exploitation. The attack requires an authenticated client with MANAGE permission, so the attacker must first obtain privileged access, limiting the threat sphere. The vulnerability is not listed in CISA KEV, but the lack of protection against deserialization of untrusted data keeps the risk significant for installations that enable message‑based management with elevated permissions.
OpenCVE Enrichment