https://seclists.org/oss-sec/2026/q3/697: CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Affected Software
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated messaging client with MANAGE permission that is authorized to use management-via-messaging. Unauthenticated clients and clients without that permission are not described as able to trigger the vulnerable processing path.
Which deployments are affected?
Affected Apache Artemis core-client versions are 2.50.0 through 2.56.0, and affected Apache ActiveMQ Artemis core-client versions are 1.3.0 through 2.44.0. Version 2.57.0 is identified as fixing the issue.
What is the impact of successful exploitation?
A crafted permitted parameter type can cause excessive computation during Java deserialization and pin a broker processing thread. This can lead to denial of service.
What can be done before upgrading?
Limit MANAGE permission and authorization for management-via-messaging to only trusted clients, since those privileges are required to reach the affected request-processing path. Upgrade to version 2.57.0 when possible.