https://seclists.org/oss-sec/2026/q2/207: CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Published Apr 23, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/activemq-broker<5.19.6, >=6.0.0<6.2.5
maven/org.apache.activemq/activemq-all<5.19.6, >=6.0.0<6.2.5
maven/org.apache.activemq/apache-activemq<5.19.6, >=6.0.0<6.2.5
Frequently Asked Questions
1
What is the severity of CVE-2026-40466?
The severity of CVE-2026-40466 is classified as important.
2
Which versions are affected by CVE-2026-40466?
Affected versions include Apache ActiveMQ Broker before 5.19.6 and 6.0.0 before 6.2.5, as well as Apache ActiveMQ All before 5.19.6.
3
How do I fix CVE-2026-40466?
To fix CVE-2026-40466, upgrade to Apache ActiveMQ Broker version 5.19.6 or later and 6.2.5 or later.
4
What issue does CVE-2026-40466 address?
CVE-2026-40466 addresses a possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI.
5
Is there a workaround for CVE-2026-40466?
There are no specific workarounds documented for CVE-2026-40466, so upgrading to the latest versions is recommended.