https://seclists.org/oss-sec/2026/q2/1062: CVE-2026-53916: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
Published Jun 29, 2026
·Updated
Affected Software
6 affected components
Apache ActiveMQ<5.19.8
Apache ActiveMQ>=6.0.0<6.2.7
maven/org.apache.activemq/activemq-all<5.19.8
maven/org.apache.activemq/activemq-all>=6.0.0<6.2.7
maven/org.apache.activemq/activemq-stomp<5.19.8
maven/org.apache.activemq/activemq-stomp>=6.0.0<6.2.7
Frequently Asked Questions
1
What is the severity of CVE-2026-53916?
The severity of CVE-2026-53916 is classified as important.
2
Which versions are affected by CVE-2026-53916?
CVE-2026-53916 affects Apache ActiveMQ versions before 5.19.8 and 6.0.0 before 6.2.7.
3
How do I fix CVE-2026-53916?
To fix CVE-2026-53916, upgrade to Apache ActiveMQ version 5.19.8 or 6.2.7 and later.
4
What component is vulnerable in CVE-2026-53916?
The vulnerability in CVE-2026-53916 exists in the STOMP NIO codec's unbounded header buffer.
5
Is CVE-2026-53916 related to specific libraries of Apache ActiveMQ?
Yes, CVE-2026-53916 affects libraries such as org.apache.activemq:apache-activemq and org.apache.activemq:activemq-all.