Search CVE reports


Toggle filters

1 – 10 of 37 results


CVE-2026-34197

Medium priority
Needs evaluation

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-33227

Medium priority
Needs evaluation

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All. In two instances (when creating a Stomp consumer and also browsing messages in the...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27446

Medium priority
Needs evaluation

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-66168

Medium priority
Needs evaluation

Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-27533

Medium priority
Needs evaluation

Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory allocation and...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2022-41678

Medium priority

Some fixes available 4 of 6

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Not affected Fixed Fixed Fixed
Show less packages

CVE-2023-46604

High priority

Some fixes available 4 of 6

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-35278

Medium priority
Needs evaluation

In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

2 affected packages

artemis, activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
artemis Needs evaluation Needs evaluation Needs evaluation Needs evaluation
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2020-13947

Medium priority
Needs evaluation

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2021-26118

Medium priority
Needs evaluation

While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production...

1 affected package

activemq

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
activemq Not affected Needs evaluation Needs evaluation Needs evaluation
Show less packages