CVE-2026-39304
Apache ActiveMQ NIO SSL transports run out of memory on repeated TLS 1.3 KeyUpdate messages
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.19.4; 6.0.0 before 6.2.4
Upstream Fix
5.19.4 and 6.2.4 (the advisory recommends 5.19.5 or 6.2.4)
Published
April 10, 2026
OSSeva Coverage
Fixed upstream
Description
The NIO SSL transports do not handle TLS 1.3 KeyUpdate messages triggered by the client correctly, so a client that sends them rapidly makes the broker exhaust its memory in the SSL engine. Earlier TLS versions hang the connection on renegotiation instead, which the same releases also fix. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.4; 6.0.0 before 6.2.4, you need this patch. Book a discovery call to get covered.