Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-49432

Apache ActiveMQ STOMP connector denial of service through a negative content-length

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.19.8; 6.0.0 before 6.2.7

Upstream Fix

5.19.8 and 6.2.7

Published

June 30, 2026

OSSeva Coverage

Fixed upstream

Description

A remote, unauthenticated peer that can reach a STOMP connector can send a negative content-length. On the NIO STOMP transport it can then keep streaming body bytes and grow the connection's command buffer past its configured limits until the broker runs out of memory. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.