CVE-2026-57822
Last modified
CVE-2026-57822 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Artemis | >= 1.3.0, < 2.44.0 |
| Apache | Artemis | >= 2.50.0, < 2.57.0 |
References
- https://lists.apache.org/thread/0jmovbbvdo22zq1r91jrlhv02ck7jqzpMailing List, Vendor Advisory
- https://www.openwall.com/lists/oss-security/2026/09/10/4Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-57822?
How severe is CVE-2026-57822?
How do I fix CVE-2026-57822?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-57815Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2026-57816Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2026-57817The OpenID Connect Core 1.0 specification mandates that the …8.1
- CVE-2026-57818A race condition in JCacheCodeDataProvider allows an attacke…8.1
- CVE-2026-57819Apache CXF allows to set a limit on the number of form param…7.5
- CVE-2026-57821A SQL Injection vulnerability exists in Apache Fineract's Of…8.1
- CVE-2026-57825In the opam package before 2.5.2 for OCaml, the sandbox prot…5.7
- CVE-2026-57826An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In…6.8
- CVE-2026-57827Joomla Extension - rsjoomla.com - Unauthenticated file uploa…9.8
- CVE-2026-57828Joomla Extension - phoca.cz - Authenticated file upload in P…8.8
- CVE-2026-57829Joomla Extension - joomshaper.com - Unauthenticated stored X…6.1
- CVE-2026-5783Improper neutralization of input during web page generation …7.6
Are you affected by CVE-2026-57822?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
