VYPR

Artemis

by Apache

Source repositories

CVEs (23)

  • CVE-2026-27446CriMar 4, 2026
    risk 0.65cvss 9.8epss 0.01

    Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled…

  • CVE-2026-67593CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through…

  • CVE-2026-49364CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. …

  • CVE-2026-57967CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from…

  • CVE-2023-50780HigOct 14, 2024
    risk 0.52cvss 8.8epss 0.17

    Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative…

  • CVE-2026-49362HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0…

  • CVE-2022-23913HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.

  • CVE-2017-12174HigMar 7, 2018
    risk 0.49cvss 7.5epss 0.06

    It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.

  • CVE-2016-4978HigSep 27, 2016
    risk 0.47cvss 7.2epss 0.07

    The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to…

  • CVE-2021-26117HigJan 27, 2021
    risk 0.43cvss 7.5epss 0.11

    The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.15.14, the anonymous context is used to verify a valid users…

  • CVE-2026-75880MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from…

  • CVE-2026-57822MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.01

    When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that…

  • CVE-2026-49363HigSep 10, 2026
    risk 0.42cvss 7.5epss 0.01

    An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through…

  • CVE-2025-27391MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled. This issue affects Apache…

  • CVE-2021-26118HigJan 27, 2021
    risk 0.42cvss 7.5epss 0.04

    While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access control for the entire session. Production of advisory messages was not subject to access control in…

  • CVE-2022-35278MedAug 23, 2022
    risk 0.40cvss 6.1epss 0.02

    In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue.

  • CVE-2020-13932MedJul 20, 2020
    risk 0.40cvss 6.1epss 0.04

    In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin;…

  • CVE-2020-10727MedJun 26, 2020
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use…

  • CVE-2021-4040MedAug 24, 2022
    risk 0.35cvss 5.3epss 0.03

    A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted…

  • CVE-2026-32642MedMar 24, 2026
    risk 0.28cvss 4.3epss 0.01

    Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authenticated user which has the…

Page 1 of 2