Description
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service.

This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.


Users are recommended to upgrade to version 2.57.0, which fixes this issue.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

An authenticated client can create a consumer whose message selector contains strategically placed wildcard characters. The broker evaluates this selector for every message that passes through, which can cause a large number of string comparisons. Because the evaluation is performed on a shared broker thread, a selector designed to trigger many comparisons can monopolize that thread, preventing other messages from being processed and effectively disabling the broker for legitimate clients. The primary consequence is denial of service that affects the availability of the messaging service.

Affected Systems

Vendors: Apache Software Foundation; Products: Apache ActiveMQ Artemis and Apache Artemis. Affected versions include Apache Artemis 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis 1.0.0 through 2.44.0. All releases within those ranges are impacted until the fix is applied.

Risk and Exploitability

Severity is medium, with a CVSS score of 6.5, based on the potential to disable a is <1%, indicating low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely documented exploitation yet. The attack requires the attacker to authenticate with the broker and establish a consumer, Because the flaw relies on unvalidated selector syntax, an attacker can choose any wildcard placement where the broker process will spend time, but the exploitation conditions remain relatively simple and do not depend on external network access beyond normal client connectivity.

Generated by OpenCVE AI on September 10, 2026 at 23:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Artemis to version 2.57.0 or later and upgrade Apache ActiveMQ Artemis to a release that incorporates the fix (any version newer than 2.44.0).
  • Restrict the use of message selectors that contain wildcard characters for authenticated consumers; implement selector syntax validation or deny wildcard usage entirely for high‑privilege users.
  • Configure broker‑level resource limits such as thread pool size, isolation, and timeouts, and monitor broker performance for signs of selector‑induced contention.

Generated by OpenCVE AI on September 10, 2026 at 23:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:apache:artemis:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache activemq Artemis
Apache artemis
Vendors & Products Apache
Apache activemq Artemis
Apache artemis

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
References

Thu, 10 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes this issue.
Title Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Weaknesses CWE-1333
References

Subscriptions

Apache Activemq Artemis Artemis
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-18T14:37:28.641Z

Reserved: 2026-08-18T12:59:58.950Z

Link: CVE-2026-75880

cve-icon Vulnrichment

Updated: 2026-09-10T05:12:01.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T05:17:01.673

Modified: 2026-09-18T15:17:11.787

Link: CVE-2026-75880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:30:12Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity