VYPR
High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026

CVE-2026-50750

CVE-2026-50750

Description

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.

Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.

Users are recommended to upgrade to version 6.2.7, which fixes the issue.

Affected products

7
  • Apache/Activemq5 versions
    cpe:2.3:a:apache:activemq:5.19.7:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:apache:activemq:5.19.7:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:activemq:6.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:activemq_broker:5.19.7:*:*:*:*:*:*:*
    • cpe:2.3:a:apache:activemq_broker:6.2.6:*:*:*:*:*:*:*
    • (no CPE)range: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7
  • Range: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7
  • osv-coords
    Range: >= 5.19.7, < 5.19.8

Patches

Vulnerability mechanics

References

1

News mentions

2