Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-49432
Apache ActiveMQ STOMP connector denial of service through a negative content-length
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.19.8; 6.0.0 before 6.2.7
Upstream Fix
5.19.8 and 6.2.7
Published
June 30, 2026
OSSeva Coverage
Fixed upstream
Description
A remote, unauthenticated peer that can reach a STOMP connector can send a negative content-length. On the NIO STOMP transport it can then keep streaming body bytes and grow the connection's command buffer past its configured limits until the broker runs out of memory. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.