CVE-2026-53916: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp.
An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer them without limit, exhausting the JVM heap. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQ (all affected packages mentioned in advisory)to a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ (all affected packages mentioned in advisory)to a version that resolves this vulnerability.Fixed in 5.19.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53916?
CVE-2026-53916 has a risk rating of 30, indicating a high severity vulnerability.
How do I fix CVE-2026-53916?
To fix CVE-2026-53916, upgrade to the latest patched version of Apache ActiveMQ that resolves this vulnerability.
Who is affected by CVE-2026-53916?
CVE-2026-53916 affects users of Apache ActiveMQ, Apache ActiveMQ All, and Apache ActiveMQ Stomp who use STOMP NIO connections.
What does CVE-2026-53916 exploit?
CVE-2026-53916 exploits an unbounded header buffer in the STOMP NIO codec, allowing unauthenticated clients to exhaust the JVM heap.
Can CVE-2026-53916 allow for remote code execution?
CVE-2026-53916 does not directly indicate the ability for remote code execution but can lead to denial of service due to resource exhaustion.