https://seclists.org/oss-sec/2026/q2/1063: CVE-2026-53917: Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWiproperty unmarshalling
Published Jun 29, 2026
·Updated
Affected Software
4 affected components
Apache ActiveMQ>6.0.0<=6.2.7, <5.19.8
Apache ActiveMQ All>6.0.0<=6.2.7, <5.19.8
Apache ActiveMQ Client>6.0.0<=6.2.7, <5.19.8
Apache ActiveMQ Broker>6.0.0<=6.2.7, <5.19.8
Frequently Asked Questions
1
What is the severity of CVE-2026-53917?
The severity of CVE-2026-53917 is classified as important.
2
Which versions of Apache ActiveMQ are affected by CVE-2026-53917?
CVE-2026-53917 affects Apache ActiveMQ versions prior to 5.19.8 and 6.0.0 before 6.2.7.
3
How do I fix CVE-2026-53917?
To fix CVE-2026-53917, update Apache ActiveMQ to version 5.19.8 or 6.2.7 or later.
4
What type of vulnerability is CVE-2026-53917?
CVE-2026-53917 is an unbounded memory allocation vulnerability found during OpenWiproperty unmarshalling.
5
What impact does CVE-2026-53917 have on Apache ActiveMQ?
CVE-2026-53917 can lead to potential denial-of-service conditions due to excessive memory consumption.