Apache ActiveMQ Classic 5.17 end of life
Apache ActiveMQ Classic 5.17 has been inactive since 12 April 2024, when the project removed it from its current releases. A final 5.17.7 followed on 14 March 2025. The project publishes no formal end date. No 5.17 release fixes CVE-2026-34197, a Jolokia code execution flaw on CISA's exploited list, or later advisories, which are fixed only in 5.19 and 6.3.
- End of life
- 12 April 2024
- Released
- Mar 2022
- Final release
- 5.17.7 (14 March 2025)
- Successor
- ActiveMQ Classic 5.19 or 6.3, or ActiveMQ Artemis
Date published by Apache ActiveMQ Classic download page. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 12 April 2024
- Releases on the 5.17.x line. The download page lists 5.17.x as inactive, which it defines as no longer maintained and not receiving updates.
- Security fixes. CVE-2026-34197 was fixed in 5.19.4 and 6.2.3, and CVE-2026-74761, a clientId spoofing flaw in durable subscription removal, in 5.19.11 and 6.3.2.
- Dependency updates. 5.17.7 bundles Spring 5.3.33 and Jetty 9.4.54, and a 5.17 build gets no newer versions of either.
What actually breaks in the upgrade
Check for CVE-2023-46604 first
The OpenWire remote code execution flaw, CVE-2023-46604, affects 5.17 before 5.17.6 and has been on CISA's Known Exploited Vulnerabilities catalogue since 2 November 2023. Any 5.17 broker below 5.17.6 is exposed to a flaw with public exploits, whatever the longer plan.
5.19 is a short hop, 6.x is not
ActiveMQ 5.19 stays on the javax.jms API and Java 11, so moving from 5.17 is a routine broker upgrade that brings current security fixes. ActiveMQ 6.x implements Jakarta Messaging on the jakarta.jms API and needs Java 17, so client applications built against javax.jms have to move too.
Artemis is a re-platform
ActiveMQ Artemis is the other ActiveMQ broker, with a different storage engine and configuration model. It accepts OpenWire clients, which eases the move, but broker configuration, persistence and operational tooling all change.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to 5.19 | Same javax.jms API and Java 11, current security fixes. | Days | Engineering time | The fastest way to close CVE-2026-34197 and CVE-2026-74761. |
| Upgrade to 6.3 | Jakarta Messaging on the Classic broker, Java 17. | Weeks to quarters | Client application changes | Right when applications are moving to Jakarta EE anyway. |
| Migrate to Artemis | A different broker that accepts OpenWire clients. | Quarters | Re-platform | Worth it for estates that will run brokers for years. |
| OSSeva patched builds on 5.17 | Signed 5.17 builds with security fixes backported. | Days | Subscription | For brokers pinned by a vendor product or a change freeze. |
What OSSeva does for Apache ActiveMQ Classic 5.17
OSSeva patches this line
OSSeva backports security fixes to ActiveMQ Classic 5.15 to 5.18, including 5.17, and delivers them as signed builds on the Patch, Assure and Operate tiers. OSSeva engineers also run the move to 5.19, 6.x or Artemis when you are ready.
Apache ActiveMQ Classic extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
US federal agencies must remediate KEV-listed vulnerabilities by the catalogue deadline. CVE-2023-46604 and CVE-2026-34197 are both listed, and no 5.17 release fixes the second.
Apache ActiveMQ Classic 5.17: common questions
When did ActiveMQ 5.17 reach end of life?
The project publishes no formal date. It removed 5.17.x from its current releases on 12 April 2024 and lists the line as inactive. A final 5.17.7 was released on 14 March 2025.
Is ActiveMQ 5.17 affected by CVE-2026-34197?
Yes. It affects ActiveMQ Classic before 5.19.4 and 6.x before 6.2.3. An authenticated attacker who can reach the Jolokia endpoint can run code on the broker. It has been on CISA's Known Exploited Vulnerabilities catalogue since 16 April 2026.
Which ActiveMQ 5.17 version fixes CVE-2023-46604?
5.17.6. Brokers and Java OpenWire clients should both be on a fixed version.
Which ActiveMQ Classic versions are supported now?
The download page lists 5.19.x and 6.3.x as active. Every other line, including 5.17, 5.18, 6.1 and 6.2, is inactive.
Can I get security patches for ActiveMQ 5.17?
Yes. OSSeva ships patched, signed 5.17 builds on the Patch, Assure and Operate tiers.
Still running Apache ActiveMQ Classic 5.17?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.