CVE-2026-53917: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker.
An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size value for the map. OpenWire message property maps are unmarshaled without size validation which can trigger OOM and crash the broker. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Client: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7.
Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Allto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQ Clientto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Clientto a version that resolves this vulnerability.Fixed in 5.19.8 - Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 6.2.7 - Upgrade
Upgrade
Apache ActiveMQ Brokerto a version that resolves this vulnerability.Fixed in 5.19.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53917?
CVE-2026-53917 has a severity rating of 30, indicating a critical risk level.
How do I fix CVE-2026-53917?
To fix CVE-2026-53917, update to the latest version of Apache ActiveMQ that addresses this vulnerability.
What systems are affected by CVE-2026-53917?
CVE-2026-53917 affects Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, and Apache ActiveMQ Broker.
What type of attack does CVE-2026-53917 enable?
CVE-2026-53917 enables an authenticated user to perform a DoS attack by sending a crafted OpenWire message with excessive size values.
What is the primary vulnerability mechanism in CVE-2026-53917?
The primary mechanism of CVE-2026-53917 is unbounded memory allocation during OpenWire property unmarshalling.