CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service.
This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0.
Users are recommended to upgrade to version 2.57.0, which fixes this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Artemis / Apache ActiveMQ Artemisto a version that resolves this vulnerability.Fixed in 2.57.0Patch CVE-2026-75880
Event History
Frequently Asked Questions
What access does an attacker need to trigger the denial of service?
The attacker must be an authenticated client capable of attaching a consumer with a message selector. The selector must use crafted wildcard patterns that cause excessive evaluation during message delivery attempts.
Which deployments are affected?
Apache Artemis versions 2.50.0 through 2.56.0 are affected. Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0 are affected.
What is the recommended remediation?
Upgrade to version 2.57.0, which fixes the issue.