CVE-2026-49432
Last modified
CVE-2026-49432 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | < 5.19.8 |
| Apache | Activemq | >= 6.0.0, < 6.2.7 |
References
- https://lists.apache.org/thread/fsjb26605syqr8xks249h8gkp86t55d2Vendor Advisory, Mailing List
- https://www.openwall.com/lists/oss-security/2026/06/29/7Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-49432?
How severe is CVE-2026-49432?
How do I fix CVE-2026-49432?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49426When auditing a system call executed via ptrace(PT_SC_REMOTE…3.3
- CVE-2026-49427Pages belonging to largepage shared memory objects were not …8.8
- CVE-2026-49428Certain system calls, such open(2) with the O_TRUNC flag set…8.4
- CVE-2026-49429The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), …7.8
- CVE-2026-49430The ZFS_IOC_RECV_NEW ioctl, in the heal receive path, simila…7.8
- CVE-2026-49431The ZFS_IOC_SET_PROP ioctl, used by zfs-set(8), incorrectly …3.3
- CVE-2026-49433The DeepAI endpoint 'https://api.deepai.org/change_user_emai…5
- CVE-2026-49434Improper Input Validation vulnerability in Apache ActiveMQ B…7.5
- CVE-2026-49435Keysight IxChariot Endpoint and associated products contain …9.8
- CVE-2026-49436LinkAce is a self-hosted archive to collect website links. P…7.3
- CVE-2026-49439OpenRemote is an open-source internet-of-things platform. Pr…4.3
- CVE-2026-4944vllm-project/vllm version 0.14.1 contains a vulnerability wh…8.8
Are you affected by CVE-2026-49432?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
