Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-75880
Apache Artemis: crafted wildcard selector ties up a shared broker thread
Technology
ActiveMQ Artemis
CVSS Score
6.5 / 10.0
Affected Versions
Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0
Upstream Fix
2.57.0
Published
September 10, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated client can attach a consumer whose message selector uses crafted wildcards, causing excessive evaluation on each delivery attempt and occupying a shared broker thread, which denies service to other clients. Apache rates it moderate; the 6.5 score on NVD is from CISA-ADP.
Is your ActiveMQ Artemis deployment affected?
If you're running Apache Artemis 2.50.0 to 2.56.0; Apache ActiveMQ Artemis 1.0.0 to 2.44.0, you need this patch. Book a discovery call to get covered.