https://seclists.org/oss-sec/2026/q3/287: CVE-2026-59878: Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS
Published Jul 27, 2026
·Updated
Affected Software
3 affected components
Apache ActiveMQ AMQP>5.19.9<6.0.0, <5.19.9, >=6.0.0<6.2.8
Apache ActiveMQ<5.19.9, >=6.0.0<6.2.8
Apache ActiveMQ All<5.19.9, >=6.0.0<6.2.8
Frequently Asked Questions
1
What is the severity of CVE-2026-59878?
The severity of CVE-2026-59878 is classified as moderate.
2
Which versions are affected by CVE-2026-59878?
CVE-2026-59878 affects Apache ActiveMQ AMQP before version 5.19.9, Apache ActiveMQ AMQP 6.0.0 before 6.2.8, and Apache ActiveMQ before version 5.19.9.
3
What is the impact of CVE-2026-59878?
CVE-2026-59878 leads to a denial of service (DoS) due to a negative frame size validation bypass.
4
How do I fix CVE-2026-59878?
To fix CVE-2026-59878, upgrade to Apache ActiveMQ AMQP 5.19.9, Apache ActiveMQ AMQP 6.2.8, or a later version.
5
Is there a workaround for CVE-2026-59878?
There are no publicly documented workarounds for CVE-2026-59878; applying the recommended upgrades is advised.