VYPR

ActiveMQ Stomp

by Apache

Source repositories

CVEs (2)

  • CVE-2026-53916HigJun 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without…

  • CVE-2026-49432HigJun 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP…