High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-50734
CVE-2026-50734
Description
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All.
An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. The value is not validate and causes the broker to attempt allocation during pre-auth negotiation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected products
5- Range: <5.19.8, >=6.0.0 <6.2.7
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/29/10nvdThird Party Advisory
- lists.apache.org/thread/nxso951fnvf72qf9m475mpz4yf931xk0nvdVendor AdvisoryMailing List
News mentions
2- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026
- Apache ActiveMQ: Nine Vulnerabilities Disclosed, Affecting Broker and Web ConsoleVypr Intelligence · Jul 2, 2026