CVE-2026-50750: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.
Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM. This issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.
Users are recommended to upgrade to version 6.2.7, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 6.2.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50750?
CVE-2026-50750 has a risk rating of 71, indicating a high level of severity.
How do I fix CVE-2026-50750?
To mitigate CVE-2026-50750, upgrade to the latest patch version of Apache ActiveMQ Broker or configure it to limit the number of BrokerInfo commands.
What systems are affected by CVE-2026-50750?
CVE-2026-50750 affects Apache ActiveMQ Broker, Apache ActiveMQ, and Apache ActiveMQ All.
What type of vulnerability is CVE-2026-50750?
CVE-2026-50750 is categorized as a Denial of Service (DoS) vulnerability stemming from an Out of Memory condition.
Can unauthenticated attackers exploit CVE-2026-50750?
Yes, CVE-2026-50750 allows unauthenticated attackers to exploit the system by sending repeated BrokerInfo commands.