Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache ActiveMQ — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Apache ActiveMQ, with AI-generated Chinese analysis, references, and POCs.

This page catalogs common weakness types associated with Apache ActiveMQ, a widely used open-source message broker from the Apache Software Foundation. It aggregates vulnerability data covering various severity levels and weakness classifications affecting this specific messaging platform over a significant historical period. Here, security professionals can track vendor advisories related to Apache ActiveMQ, gain a deeper understanding of the underlying weakness classes exploited in this environment, and review the complete vulnerability history of the product. This resource is designed to help teams assess risk, prioritize remediation efforts, and maintain security postures by providing a centralized view of known issues. By consolidating these records, the page supports informed decision-making for administrators and developers who rely on Apache ActiveMQ for enterprise integration and asynchronous communication. The information presented is structured to facilitate efficient searching and analysis, allowing users to identify patterns in vulnerabilities and apply appropriate patches or configurations. It serves as a reference for compliance audits and security assessments, ensuring that all relevant weaknesses are accounted for in the overall security strategy. Readers can explore detailed descriptions of each vulnerability, understand their impact on system confidentiality, integrity, and availability, and stay updated with the latest security developments for this critical infrastructure component.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-49432 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service CWE-20--2026-06-30
CVE-2026-49877 Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console CWE-285--2026-06-30
CVE-2026-52760 Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console CWE-79--2026-06-30
CVE-2026-53916 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec CWE-789--2026-06-30
CVE-2026-53917 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling CWE-789--2026-06-30
CVE-2026-42253 Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties CWE-79--2026-06-01
CVE-2026-49157 Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default CWE-276--2026-06-01
CVE-2026-41044 Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia CWE-20 7.2AIHighAI2026-04-24
CVE-2026-41043 Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues CWE-79 5.4AIMediumAI2026-04-24
CVE-2026-40046 Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated CWE-190 9.8AICriticalAI2026-04-09
CVE-2025-66168 Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated CWE-190 5.4 Medium2026-03-04
CVE-2025-27533 Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation CWE-789 7.5AIHighAI2025-05-07
CVE-2024-32114 Apache ActiveMQ: Jolokia and REST API were not secured with default configuration CWE-1188 8.5 High2024-05-02
CVE-2022-41678 Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE CWE-287 8.8 -2023-11-28
CVE-2023-46604 Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack CWE-502 10.0 Critical2023-10-27
CVE-2020-13947 Apache ActiveMQ 跨站脚本漏洞 6.1 -2021-02-08
CVE-2021-26117 ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind CWE-287 7.5 -2021-01-27
CVE-2020-11998 Apache ActiveMQ 代码注入漏洞 8.1 -2020-09-10
CVE-2020-13920 Apache ActiveMQ effect 授权问题漏洞 5.9 -2020-09-10
CVE-2020-1941 Apache ActiveMQ 跨站脚本漏洞 6.1 -2020-05-14
CVE-2019-0222 Apache ActiveMQ 代码注入漏洞 7.5 -2019-03-28
CVE-2018-8006 Apache ActiveMQ 跨站脚本漏洞 6.1 -2018-10-10
CVE-2018-11775 Apache ActiveMQ Client 信任管理问题漏洞 7.4 -2018-09-10
CVE-2017-15709 ActiveMQ 信息泄露漏洞 5.9 -2018-02-13
CVE-2016-6810 Apache ActiveMQ 跨站脚本漏洞 6.1 -2018-01-10

All 25 known CVE vulnerabilities affecting Apache ActiveMQ with full Chinese analysis, references, and POCs where available.