Where
-Infinity
0

Severity: low

Affected versions:

- Apache ActiveMQ Client (org.apache.activemq:activemq-client) before 5.19.3 - Apache ActiveMQ Client (org.apache.activemq:activemq-client) 6.0.0 before 6.2.2 - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.3 - Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.2 - Apache ActiveMQ (org.apache.activemq:activemq-all) before 5.19.3 - Apache ActiveMQ (org.apache.activemq:activemq-all) 6.0.0 before 6.2.2 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.3 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.2

Description:

Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All.

In two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user provided "key" value could be constructed to traverse the classpath due to path concatenation. As a result, the application is exposed to a classpath path resource loading vulnerability that could potentially be chained together with another attack to lead to exploit.This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache ActiveMQ All: before 5.19.3, from 6.0.0 before 6.2.2.

Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue. Note: 5.19.3 and 6.2.2 also fix this issue, but that is limited to non-Windows environments due to a path separator resolution bug fixed in 5.19.4 and 6.2.3.

Credit:

Dawei Wang (finder)

References:

https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-33227

First published (updated )

Severity: important

Affected versions:

- Apache ActiveMQ (org.apache.activemq:apache-activemq) before 5.19.6 - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.2.5 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.6 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.5

Description:

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.

An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to be HTML (instead of XML) and by injecting HTML into a JMS selector field.

This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Web: before 5.19.6, from 6.0.0 before 6.2.5.

Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

Credit:

Khaled Alshammri (finder)

References:

https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-41043

Severity: important

Affected versions:

- Apache ActiveMQ (org.apache.activemq:apache-activemq) before 5.19.7 - Apache ActiveMQ (org.apache.activemq:apache-activemq) 6.0.0 before 6.2.6 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.7 - Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.6

Description:

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.

The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response header without any validation. This can allow overwriting and injecting security headers by setting them on JMS messages that are returned by the servlet.

This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6; Apache ActiveMQ Web: before 5.19.7, from 6.0.0 before 6.2.6.

Users are recommended to upgrade to version 5.19.7 or 6.2.6, which fixes the issue. The MessageServlet has now been deprecated and disabled by default.

Credit:

Vishal Shukla (finder) pyn3rd (finder) uname (finder) 4ra1n (finder)

References:

https://activemq.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-42253

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203