Impact
An authenticated client can create a consumer whose message selector contains strategically placed wildcard characters. The broker evaluates this selector for every message that passes through, which can cause a large number of string comparisons. Because the evaluation is performed on a shared broker thread, a selector designed to trigger many comparisons can monopolize that thread, preventing other messages from being processed and effectively disabling the broker for legitimate clients. The primary consequence is denial of service that affects the availability of the messaging service.
Affected Systems
Vendors: Apache Software Foundation; Products: Apache ActiveMQ Artemis and Apache Artemis. Affected versions include Apache Artemis 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis 1.0.0 through 2.44.0. All releases within those ranges are impacted until the fix is applied.
Risk and Exploitability
Severity is medium, with a CVSS score of 6.5, based on the potential to disable a is <1%, indicating low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely documented exploitation yet. The attack requires the attacker to authenticate with the broker and establish a consumer, Because the flaw relies on unvalidated selector syntax, an attacker can choose any wildcard placement where the broker process will spend time, but the exploitation conditions remain relatively simple and do not depend on external network access beyond normal client connectivity.
OpenCVE Enrichment