VendorsApacheactivemqall versions
Vulnerabilities

Apache Software Foundation ActiveMQ

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

75CVEs
CVE-2023-46604
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
Published 2023-10-27 · Analyzed
10.0KEVEPSS 0.997
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
Published 2021-03-22 · Analyzed
9.9EPSS 0.723
CVE-2016-3088
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
Published 2016-06-01 · Analyzed
9.8KEV2 PoCEPSS 0.985
CVE-2013-7285
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.
Published 2019-05-15 · Analyzed
9.81 PoCEPSS 0.844
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.764
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.760
CVE-2020-11998
A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open to the following attack: https://docs.oracle.com/javase/8/docs/technotes/guides/management/agent.html "A remote client could create a javax.management.loading.MLet MBean and use it to create new MBeans from arbitrary URLs, at least if there is no security manager. In other words, a rogue remote client could make your Java application execute arbitrary code." Mitigation: Upgrade to Apache ActiveMQ 5.15.13
Published 2020-09-10 · Modified
9.8EPSS 0.512
CVE-2015-5254
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Published 2016-01-08 · Modified
9.8EPSS 0.382
CVE-2021-21350
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.152
CVE-2021-21347
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.143
CVE-2014-3600
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Published 2017-10-27 · Modified
9.8EPSS 0.097
CVE-2020-26217
Remote Code Execution in XStream
Published 2020-11-16 · Analyzed
9.3EPSS 0.850
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.1EPSS 0.821
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
9.1EPSS 0.500
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Published 2026-04-07 · Analyzed
8.8KEVEPSS 0.983
CVE-2022-41678
Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE
Published 2023-11-28 · Modified
8.8EPSS 0.858
CVE-2024-32114
Apache ActiveMQ: Jolokia and REST API were not secured with default configuration
Published 2024-05-02 · Analyzed
8.8EPSS 0.071
CVE-2026-40466
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Published 2026-04-24 · Modified
8.8EPSS 0.048
CVE-2026-41044
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
Published 2026-04-24 · Modified
8.8EPSS 0.010
CVE-2025-66168
Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated
Published 2026-03-04 · Modified
8.8EPSS 0.008
CVE-2026-45505
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
Published 2026-06-01 · Analyzed
8.8EPSS 0.006
CVE-2026-49157
Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
Published 2026-06-01 · Analyzed
8.8EPSS 0.004
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
8.6EPSS 0.468
CVE-2026-42588
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
Published 2026-06-01 · Analyzed
8.1EPSS 0.007
CVE-2026-49877
Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
Published 2026-06-30 · Analyzed
8.1EPSS 0.005
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
Published 2021-03-22 · Analyzed
7.8EPSS 0.138
CVE-2021-21341
XStream can cause a Denial of Service
Published 2021-03-22 · Analyzed
7.5EPSS 0.778
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Published 2021-03-22 · Analyzed
7.5EPSS 0.467
CVE-2014-3576
The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of service (shutdown) via a shutdown command.
Published 2015-08-14 · Modified
7.5EPSS 0.128
CVE-2019-0222
In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.
Published 2019-03-28 · Modified
7.5EPSS 0.120
CVE-2021-26117
ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind
Published 2021-01-27 · Modified
7.5EPSS 0.113
CVE-2025-27533
Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
Published 2025-05-07 · Modified
7.51 PoCEPSS 0.087
CVE-2014-3612
The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6524 for the use of wildcard operators in usernames.
Published 2015-08-24 · Modified
7.5EPSS 0.072
CVE-2026-39304
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
Published 2026-04-10 · Modified
7.5EPSS 0.009
CVE-2026-49432
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service
Published 2026-06-30 · Analyzed
7.5EPSS 0.008
CVE-2026-53917
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-53916
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-50734
Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-50750
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-74761
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Published 2026-09-09 · Analyzed
7.5EPSS 0.006
1 / 2Next →