Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-101292

ActiveMQ Artemis federation instantiates arbitrary classes named by a peer

Technology

ActiveMQ Artemis

CVSS Score

8.2 / 10.0

Affected Versions

ActiveMQ Artemis before 2.34.0

Upstream Fix

2.34.0

Published

September 28, 2026

OSSeva Coverage

Fixed upstream

Description

FederationStreamConnectMessage.getFederationPolicy() loads and instantiates a class named in the CORE protocol buffer without checking its type. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet naming any class visible to the Artemis module classloader, whose static initialiser and no-argument constructor run before the cast. The record was published by Red Hat as CNA.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running ActiveMQ Artemis before 2.34.0, you need this patch. Book a discovery call to get covered.