CVE-2026-101292
ActiveMQ Artemis federation instantiates arbitrary classes named by a peer
Technology
ActiveMQ Artemis
CVSS Score
8.2 / 10.0
Affected Versions
ActiveMQ Artemis before 2.34.0
Upstream Fix
2.34.0
Published
September 28, 2026
OSSeva Coverage
Fixed upstream
Description
FederationStreamConnectMessage.getFederationPolicy() loads and instantiates a class named in the CORE protocol buffer without checking its type. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet naming any class visible to the Artemis module classloader, whose static initialiser and no-argument constructor run before the cast. The record was published by Red Hat as CNA.
Is your ActiveMQ Artemis deployment affected?
If you're running ActiveMQ Artemis before 2.34.0, you need this patch. Book a discovery call to get covered.