Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-39304

Apache ActiveMQ NIO SSL transports run out of memory on repeated TLS 1.3 KeyUpdate messages

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.19.4; 6.0.0 before 6.2.4

Upstream Fix

5.19.4 and 6.2.4 (the advisory recommends 5.19.5 or 6.2.4)

Published

April 10, 2026

OSSeva Coverage

Fixed upstream

Description

The NIO SSL transports do not handle TLS 1.3 KeyUpdate messages triggered by the client correctly, so a client that sends them rapidly makes the broker exhaust its memory in the SSL engine. Earlier TLS versions hang the connection on renegotiation instead, which the same releases also fix. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.4; 6.0.0 before 6.2.4, you need this patch. Book a discovery call to get covered.