Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-57822

Apache Artemis: management-via-messaging parameter deserialization can pin a broker thread

Technology

ActiveMQ Artemis

CVSS Score

6.5 / 10.0

Affected Versions

Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.3.0 to 2.44.0

Upstream Fix

2.57.0

Published

September 10, 2026

OSSeva Coverage

Fixed upstream

Description

When the broker processes a message-based management request from an authenticated client with MANAGE permission, parameter processing can deserialize method parameters the broker never uses. A crafted payload causes excessive computation and pins the processing thread, denying service. Apache rates it important; the 6.5 score on NVD is from CISA-ADP.

Upstream record: NVD · CVE.org

Is your ActiveMQ Artemis deployment affected?

If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.3.0 to 2.44.0, you need this patch. Book a discovery call to get covered.