Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-53917

Apache ActiveMQ unbounded memory allocation when unmarshalling OpenWire message properties

Technology

Apache ActiveMQ

CVSS Score

7.5 / 10.0

Affected Versions

before 5.19.8; 6.0.0 before 6.2.7

Upstream Fix

5.19.8 and 6.2.7

Published

June 30, 2026

OSSeva Coverage

Fixed upstream

Description

OpenWire message property maps are unmarshalled without validating their encoded size. An authenticated user can send a message that declares a very large map and run the broker out of memory. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your Apache ActiveMQ deployment affected?

If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.