https://seclists.org/oss-sec/2026/q2/755: CVE-2026-42253: Apache ActiveMQ, Apache ActiveMQ Web: HTTP sponse Header Injection via JMS Message Properties
Published May 31, 2026
·Updated
Affected Software
2 affected components
maven/org.apache.activemq/apache-activemq<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/activemq-web<5.19.7, >=6.0.0<6.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-42253?
The severity of CVE-2026-42253 is classified as important.
2
Which versions of Apache ActiveMQ are affected by CVE-2026-42253?
Apache ActiveMQ versions before 5.19.7 and 6.0.0 before 6.2.6 are affected by CVE-2026-42253.
3
Which versions of Apache ActiveMQ Web are impacted by CVE-2026-42253?
Apache ActiveMQ Web versions before 5.19.7 are impacted by CVE-2026-42253.
4
How do I fix CVE-2026-42253?
To fix CVE-2026-42253, upgrade to Apache ActiveMQ version 5.19.7 or later, or version 6.2.6 or later.
5
What vulnerability does CVE-2026-42253 address?
CVE-2026-42253 addresses an HTTP response header injection vulnerability via JMS message properties.