https://seclists.org/oss-sec/2026/q2/1056: CVE-2026-49432: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service
Published Jun 29, 2026
·Updated
Affected Software
6 affected components
Apache ActiveMQ<5.19.8
Apache ActiveMQ>6.0.0<=6.2.7
maven/org.apache.activemq/activemq-all<5.19.8
maven/org.apache.activemq/activemq-all>6.0.0<=6.2.7
maven/org.apache.activemq/activemq-stomp<5.19.8
maven/org.apache.activemq/activemq-stomp>6.0.0<=6.2.7
Frequently Asked Questions
1
What is the severity of CVE-2026-49432?
The severity of CVE-2026-49432 is categorized as important.
2
What versions are affected by CVE-2026-49432?
CVE-2026-49432 affects Apache ActiveMQ before version 5.19.8 and versions 6.0.0 before 6.2.7.
3
How do I fix CVE-2026-49432?
To fix CVE-2026-49432, upgrade Apache ActiveMQ to version 5.19.8 or 6.2.7 or later.
4
What is the nature of the vulnerability in CVE-2026-49432?
CVE-2026-49432 relates to a denial-of-service vulnerability caused by STOMP negative content-length.
5
Is there a workaround for CVE-2026-49432?
There is no specific workaround for CVE-2026-49432, so applying the necessary updates is recommended.