High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-53917
CVE-2026-53917
Description
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker.
An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are unmarshaled without size validation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected products
6- Range: <5.19.8, >=6.0.0 <6.2.7
- Range: <5.19.8, >=6.0.0 <6.2.7
Patches
Vulnerability mechanics
References
2- www.openwall.com/lists/oss-security/2026/06/29/14nvdThird Party Advisory
- lists.apache.org/thread/grrd1mwgkgblqjbwkkq6dvmdxd9ov2dxnvdVendor Advisory
News mentions
4- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Multiple Apache ActiveMQ Vulnerabilities Enable DoS Attacks and Lead to CrashesCyber Security News · Jul 3, 2026
- Apache Software Foundation: 21 Vulnerabilities Across Multiple Products Disclosed in Early July 2026Vypr Intelligence · Jul 3, 2026
- Apache ActiveMQ: Nine Vulnerabilities Disclosed, Affecting Broker and Web ConsoleVypr Intelligence · Jul 2, 2026