CVE-2026-101292: Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATIONDOWNSTREAMCONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Artemisto a version that resolves this vulnerability.Fixed in 2.34.0
Event History
Frequently Asked Questions
Who is exposed to this issue?
Apache ActiveMQ Artemis deployments before 2.34.0 that accept federation connections are exposed. Exploitation requires an authenticated federation peer.
What does an attacker need to do to exploit it?
The attacker needs to send a FEDERATION_DOWNSTREAM_CONNECT packet containing a crafted class name. The referenced class must be visible to the Artemis module classloader and have side effects in a static initializer or no-argument constructor.
What impact can exploitation have?
Loading and instantiating the attacker-selected visible class occurs before type validation. This can cause denial of service through system-property poisoning or classloading-related memory exhaustion, and may allow broker state manipulation.