End of life

Apache ActiveMQ Classic 5.17 end of life

Apache ActiveMQ Classic 5.17 has been inactive since 12 April 2024, when the project removed it from its current releases. A final 5.17.7 followed on 14 March 2025. The project publishes no formal end date. No 5.17 release fixes CVE-2026-34197, a Jolokia code execution flaw on CISA's exploited list, or later advisories, which are fixed only in 5.19 and 6.3.

End of life
12 April 2024
Released
Mar 2022
Final release
5.17.7 (14 March 2025)
Successor
ActiveMQ Classic 5.19 or 6.3, or ActiveMQ Artemis

Date published by Apache ActiveMQ Classic download page. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 12 April 2024

  • Releases on the 5.17.x line. The download page lists 5.17.x as inactive, which it defines as no longer maintained and not receiving updates.
  • Security fixes. CVE-2026-34197 was fixed in 5.19.4 and 6.2.3, and CVE-2026-74761, a clientId spoofing flaw in durable subscription removal, in 5.19.11 and 6.3.2.
  • Dependency updates. 5.17.7 bundles Spring 5.3.33 and Jetty 9.4.54, and a 5.17 build gets no newer versions of either.

What actually breaks in the upgrade

Check for CVE-2023-46604 first

The OpenWire remote code execution flaw, CVE-2023-46604, affects 5.17 before 5.17.6 and has been on CISA's Known Exploited Vulnerabilities catalogue since 2 November 2023. Any 5.17 broker below 5.17.6 is exposed to a flaw with public exploits, whatever the longer plan.

5.19 is a short hop, 6.x is not

ActiveMQ 5.19 stays on the javax.jms API and Java 11, so moving from 5.17 is a routine broker upgrade that brings current security fixes. ActiveMQ 6.x implements Jakarta Messaging on the jakarta.jms API and needs Java 17, so client applications built against javax.jms have to move too.

Artemis is a re-platform

ActiveMQ Artemis is the other ActiveMQ broker, with a different storage engine and configuration model. It accepts OpenWire clients, which eases the move, but broker configuration, persistence and operational tooling all change.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to 5.19Same javax.jms API and Java 11, current security fixes.DaysEngineering timeThe fastest way to close CVE-2026-34197 and CVE-2026-74761.
Upgrade to 6.3Jakarta Messaging on the Classic broker, Java 17.Weeks to quartersClient application changesRight when applications are moving to Jakarta EE anyway.
Migrate to ArtemisA different broker that accepts OpenWire clients.QuartersRe-platformWorth it for estates that will run brokers for years.
OSSeva patched builds on 5.17Signed 5.17 builds with security fixes backported.DaysSubscriptionFor brokers pinned by a vendor product or a change freeze.

What OSSeva does for Apache ActiveMQ Classic 5.17

OSSeva patches this line

OSSeva backports security fixes to ActiveMQ Classic 5.15 to 5.18, including 5.17, and delivers them as signed builds on the Patch, Assure and Operate tiers. OSSeva engineers also run the move to 5.19, 6.x or Artemis when you are ready.

Apache ActiveMQ Classic extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

CISA BOD 22-01

US federal agencies must remediate KEV-listed vulnerabilities by the catalogue deadline. CVE-2023-46604 and CVE-2026-34197 are both listed, and no 5.17 release fixes the second.

Compliance library Every ActiveMQ Classic version and end-of-life date

Apache ActiveMQ Classic 5.17: common questions

When did ActiveMQ 5.17 reach end of life?

The project publishes no formal date. It removed 5.17.x from its current releases on 12 April 2024 and lists the line as inactive. A final 5.17.7 was released on 14 March 2025.

Is ActiveMQ 5.17 affected by CVE-2026-34197?

Yes. It affects ActiveMQ Classic before 5.19.4 and 6.x before 6.2.3. An authenticated attacker who can reach the Jolokia endpoint can run code on the broker. It has been on CISA's Known Exploited Vulnerabilities catalogue since 16 April 2026.

Which ActiveMQ 5.17 version fixes CVE-2023-46604?

5.17.6. Brokers and Java OpenWire clients should both be on a fixed version.

Which ActiveMQ Classic versions are supported now?

The download page lists 5.19.x and 6.3.x as active. Every other line, including 5.17, 5.18, 6.1 and 6.2, is inactive.

Can I get security patches for ActiveMQ 5.17?

Yes. OSSeva ships patched, signed 5.17 builds on the Patch, Assure and Operate tiers.

Still running Apache ActiveMQ Classic 5.17?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.