Back to Vulnerability Directory
HIGHFixed upstream
CVE-2026-53917
Apache ActiveMQ unbounded memory allocation when unmarshalling OpenWire message properties
Technology
Apache ActiveMQ
CVSS Score
7.5 / 10.0
Affected Versions
before 5.19.8; 6.0.0 before 6.2.7
Upstream Fix
5.19.8 and 6.2.7
Published
June 30, 2026
OSSeva Coverage
Fixed upstream
Description
OpenWire message property maps are unmarshalled without validating their encoded size. An authenticated user can send a message that declares a very large map and run the broker out of memory. Apache rates the issue important; the 7.5 score on NVD is from CISA-ADP.
Is your Apache ActiveMQ deployment affected?
If you're running before 5.19.8; 6.0.0 before 6.2.7, you need this patch. Book a discovery call to get covered.