https://seclists.org/oss-sec/2026/q3/700: CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Published Sep 9, 2026
·Updated
Affected Software
2 affected components
Apache ARTEMIS>=2.50.0<=2.56.0
Apache ActiveMQ Artemis>=1.0.0<=2.44.0
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be able to authenticate as a client to the broker and attach a consumer using a crafted message selector. The issue is therefore relevant where untrusted or insufficiently trusted users can create consumers.
2
What is the operational impact?
Crafted wildcard usage in a selector can cause excessive evaluation during message delivery attempts. This can occupy a shared broker thread and result in denial of service.
3
Which versions need to be remediated?
Apache Artemis with org.apache.artemis:artemis-selector versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis with org.apache.activemq:artemis-selector versions 1.0.0 through 2.44.0 are affected. Upgrade to version 2.57.0 to fix the issue.