CVE-2026-49432: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service
Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQ Stompto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Stompto a version that resolves this vulnerability.Fixed in 6.2.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49432?
CVE-2026-49432 has a high severity rating of 7.5 according to the CVSS 3.1 scoring.
How do I fix CVE-2026-49432?
To fix CVE-2026-49432, upgrade to a patched version of Apache ActiveMQ that addresses the improper input validation.
What systems are affected by CVE-2026-49432?
CVE-2026-49432 affects Apache ActiveMQ, Apache ActiveMQ All, and Apache ActiveMQ Stomp implementations.
What kind of attack does CVE-2026-49432 enable?
CVE-2026-49432 allows an attacker to trigger a denial-of-service condition through a negative content-length input.
Is authentication required to exploit CVE-2026-49432?
No, CVE-2026-49432 can be exploited by a remote unauthenticated peer that can access an exposed STOMP connector.