High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-50750
CVE-2026-50750
Description
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
Affected products
7cpe:2.3:a:apache:activemq:5.19.7:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:apache:activemq:5.19.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq:6.2.6:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq_broker:5.19.7:*:*:*:*:*:*:*
- cpe:2.3:a:apache:activemq_broker:6.2.6:*:*:*:*:*:*:*
- (no CPE)range: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7
- Range: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/nhkmbdym61yp6wwy0dny8w1p46sm87krnvdVendor AdvisoryMailing List
News mentions
2- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026
- Apache ActiveMQ: Nine Vulnerabilities Disclosed, Affecting Broker and Web ConsoleVypr Intelligence · Jul 2, 2026