https://seclists.org/oss-sec/2026/q2/70: CVE-2026-39304: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorct handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
Published Apr 9, 2026
·Updated
Affected Software
4 affected components
maven/org.apache.activemq/activemq-client<5.19.4, >=6.0.0<6.2.4
maven/org.apache.activemq/activemq-broker<5.19.4, >=6.0.0<6.2.4
maven/org.apache.activemq/activemq-all<5.19.4, >=6.0.0<6.2.4
maven/org.apache.activemq/apache-activemq<5.19.4, >=6.0.0<6.2.4
Frequently Asked Questions
1
What is the severity of CVE-2026-39304?
CVE-2026-39304 has been rated as important in severity.
2
What versions are affected by CVE-2026-39304?
CVE-2026-39304 affects Apache ActiveMQ Client and Broker versions before 5.19.4 and several other versions before 6.2.4.
3
How do I fix CVE-2026-39304?
To fix CVE-2026-39304, upgrade to Apache ActiveMQ Client version 5.19.4 or later, and Broker version 5.19.4 or later.
4
What exploit does CVE-2026-39304 enable?
CVE-2026-39304 can be exploited to cause a Denial of Service (DoS) via Out of Memory (OOM) conditions.
5
Is CVE-2026-39304 related to TLSv1.3?
Yes, CVE-2026-39304 involves incorrect handling of TLSv1.3 KeyUpdate.