Bug#1144412: activemq: CVE-2026-59878 CVE-2026-61487

Salvatore Bonaccorso <[email protected]>
Newsgroups gmane.linux.debian.devel.bugs.rc
Message-ID <178673312499.1287561.2498624683884880656.reportbug__36824.5325794973$1786733243$gmane$org@eldamar.lan>
Source: activemq
Version: 5.17.6+dfsg-2
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for activemq.

CVE-2026-59878[0]:
| Improper Input Validation vulnerability in Apache ActiveMQ AMQP,
| Apache ActiveMQ, Apache ActiveMQ All.  A remote unauthenticated peer
| that can reach an exposed AMQP NIO connector can trigger denial-of-
| service behavior by sending a frame size value. This cause the NIO
| threads to die and if done rapidly enough can lead to exhaustion of
| the NIO thread pool denying service to other connections. This issue
| affects Apache ActiveMQ AMQP: before 5.19.9, from 6.0.0 before
| 6.2.8; Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8;
| Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8.  Users
| are recommended to upgrade to version 5.19.9, 6.2.8, or 6.3.0 which
| fixes the issue.


CVE-2026-61487[1]:
| Improper Authorization vulnerability in Apache ActiveMQ Broker,
| Apache ActiveMQ All, Apache ActiveMQ.   An authenticated low-
| privilege user can bypass a per-destination write ACL by sending to
| an ActiveMQ temporary composite destination whose physical name is a
| comma-separated composite of real queues. This allows publishing
| messages to any of the destinations in the list without proper write
| ACL permissions because the authorization check is bypassed due to
| the composite destination being marked as temporary. This issue
| affects Apache ActiveMQ Broker: before 5.19.9, from 6.0.0 before
| 6.2.8; Apache ActiveMQ All: before 5.19.9, from 6.0.0 before 6.2.8;
| Apache ActiveMQ: before 5.19.9, from 6.0.0 before 6.2.8.  Users are
| recommended to upgrade to version 5.19.9, 6.2.8 or 6.3.0, which
| fixes the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59878
    https://www.cve.org/CVERecord?id=CVE-2026-59878
[1] https://security-tracker.debian.org/tracker/CVE-2026-61487
    https://www.cve.org/CVERecord?id=CVE-2026-61487

Regards,
Salvatore
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.