CVE-2026-59878
Last modified
CVE-2026-59878 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value. This cause the NIO threads to die and if done rapidly enough can lead to exhaustion of the NIO thread pool denying service to other connections. This issue affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8. Users are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which fixes the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Activemq | < 5.19.9 |
| Apache | Activemq | >= 6.0.0, < 6.2.8 |
| Apache | Activemq All | < 5.19.9 |
| Apache | Activemq All | >= 6.0.0, < 6.2.8 |
| Apache | Activemq Amqp | < 5.19.9 |
| Apache | Activemq Amqp | >= 6.0.0, < 6.2.8 |
References
- https://lists.apache.org/thread/dnyx4d2oldshcj4lthso7b53y4bqmjvnMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/27/7Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59878?
How severe is CVE-2026-59878?
How do I fix CVE-2026-59878?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59871node-tar is a tar archive manipulation library for Node.js. …7.5
- CVE-2026-59873node-tar is a tar archive manipulation library for Node.js. …7.5
- CVE-2026-59874node-tar is a tar archive manipulation library for Node.js. …7.5
- CVE-2026-59875node-tar is a tar archive manipulation library for Node.js. …5.3
- CVE-2026-59876protobufjs compiles protobuf definitions into JavaScript (JS…4.8
- CVE-2026-59877protobufjs compiles protobuf definitions into JavaScript (JS…7.5
- CVE-2026-59879Immutable.js provides many Persistent Immutable data structu…7.5
- CVE-2026-5988A vulnerability was detected in Tenda F451 1.0.0.7. This imp…8.8
- CVE-2026-59880Immutable.js provides many Persistent Immutable data structu…7.5
- CVE-2026-59881AIOHTTP is an asynchronous HTTP client/server framework for …6.9
- CVE-2026-59882guzzlehttp/psr7 is a PSR-7 HTTP message library implementati…6.5
- CVE-2026-59883Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, Co…6.1
Are you affected by CVE-2026-59878?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
