VendorsApacheartemisany version
Vulnerabilities

Apache Software Foundation Artemis any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2026-27446
Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation
Published 2026-03-04 · Modified
9.8EPSS 0.100
CVE-2026-57967
Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment
Published 2026-09-10 · Analyzed
9.8EPSS 0.007
CVE-2026-67593
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
Published 2026-09-10 · Analyzed
9.1EPSS 0.006
CVE-2026-49364
Apache Artemis, Apache Artemis, Apache ActiveMQ Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
Published 2026-09-10 · Analyzed
9.1EPSS 0.004
CVE-2023-50780
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
Published 2024-10-14 · Modified
8.8EPSS 0.175
CVE-2017-12174
It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message. This may result in a heap memory exhaustion, full GC, or OutOfMemoryError.
Published 2018-03-07 · Modified
7.8EPSS 0.060
CVE-2021-26117
ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind
Published 2021-01-27 · Modified
7.5EPSS 0.113
CVE-2022-23913
Apache ActiveMQ Artemis DoS
Published 2022-02-04 · Modified
7.5EPSS 0.027
CVE-2026-49362
Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Published 2026-09-10 · Analyzed
7.5EPSS 0.006
CVE-2026-49363
Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
Published 2026-09-10 · Analyzed
7.5EPSS 0.005
CVE-2016-4978
The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.
Published 2016-09-27 · Modified
7.2EPSS 0.069
CVE-2025-27391
Apache ActiveMQ Artemis: Passwords leaking from broker properties in the debug log
Published 2025-04-09 · Analyzed
6.8EPSS 0.004
CVE-2026-57822
Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Published 2026-09-10 · Analyzed
6.5EPSS 0.005
CVE-2026-75880
Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Published 2026-09-10 · Analyzed
6.5EPSS 0.004
CVE-2020-13932
In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is being injected into the admin console's browser. The XSS payload is triggered in the diagram plugin; queue node and the info section.
Published 2020-07-20 · Modified
6.1EPSS 0.043
CVE-2022-35278
HTML Injection in ActiveMQ Artemis Web Console
Published 2022-08-23 · Modified
6.1EPSS 0.017
CVE-2020-10727
A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local attacker can use this flaw to read the contents of the Artemis shadow file.
Published 2020-06-26 · Modified
5.5EPSS 0.007
CVE-2021-4040
A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to partially disrupt availability to the broker through a sustained attack of maliciously crafted messages. The highest threat from this vulnerability is system availability.
Published 2022-08-24 · Modified
5.3EPSS 0.031
CVE-2025-27427
Apache ActiveMQ Artemis: Address routing-type can be updated by user without the createAddress permission
Published 2025-04-01 · Analyzed
4.3EPSS 0.006
CVE-2026-32642
Apache Artemis, Apache ActiveMQ Artemis: Temporary address auto-created for OpenWire consumer without createAddress permission
Published 2026-03-24 · Analyzed
4.3EPSS 0.004
CVE-2026-40914
Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-type can be updated by STOMP protocol user without the createAddress permission
Published 2026-05-28 · Modified
4.3EPSS 0.004