VYPR

Activemq Artemis

by Apache

Source repositories

CVEs (17)

  • CVE-2026-27446CriMar 4, 2026
    risk 0.65cvss 9.8epss 0.01

    Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled…

  • CVE-2026-67593CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through…

  • CVE-2026-49364CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. …

  • CVE-2026-57967CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from…

  • CVE-2023-50780HigOct 14, 2024
    risk 0.52cvss 8.8epss 0.17

    Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative…

  • CVE-2026-49362HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0…

  • CVE-2022-23913HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

  • CVE-2026-75880MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from…

  • CVE-2026-57822MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that…

  • CVE-2026-49363HigSep 10, 2026
    risk 0.42cvss 7.5epss 0.01

    An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through…

  • CVE-2025-27391MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache…

  • CVE-2021-26118HigJan 27, 2021
    risk 0.42cvss 7.5epss 0.04

    While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in…

  • CVE-2022-35278MedAug 23, 2022
    risk 0.40cvss 6.1epss 0.02

    In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

  • CVE-2020-13932MedJul 20, 2020
    risk 0.40cvss 6.1epss 0.04

    In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin;…

  • CVE-2026-32642MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.01

    Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the…

  • CVE-2026-40914MedMay 28, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user doesn't have the…

  • CVE-2025-27427MedApr 1, 2025
    risk 0.21cvss 4.3epss 0.01

    A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular…