CVE-2026-39304Disclosure(apache / activemq)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache activemq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients. This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS. Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM. Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well. This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
activemqactivemq_broker

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-12: 1Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 104-1004-1204-1404-19
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-121
Disclosure1
2026-04-141
Patch1
2026-04-191
Disclosure1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Apache ActiveMQ patches critical TLSv1.3 memory exhaustion (CVE-2026-39304) and an MQTT regression. Upgrade to 6.2.4 or 5.19.5 to secure your broker! #ActiveMQ #CyberSecurity #InfoSec #PatchAlert #TLS #MQTT #DenialOfService https://securityonline.info/apache-activemq-security-tls-mqtt-vulnerability-2026/ https://t.co/6mNGevC7X1

    Post summary

    Apache ActiveMQ has released patches for CVE-2026-39304, a critical TLSv1.3 memory exhaustion vulnerability; upgrading to 6.2.4 or 5.19.5 secures the broker.

    00011206
    11.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache ActiveMQ CVE-2026-39304: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM https://www.openwall.com/lists/oss-security/2026/04/09/17 CVE-2026-40046: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated https://www.openwall.com/lists/oss-security/2026/04/09/18

    Post summary

    The post announces two new ActiveMQ CVEs, describing their technical impact while providing links to openwall discussions but no exploit code or mitigation advice.

    00010508
    4.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Apache ActiveMQ vulnerable to DoS via OOM (CVE-2026-39304). Review resource limits and network access for your #ApacheActiveMQ instances. #DoS #infosec https://www.pulsepatch.io/posts/cve-2026-39304-apache-activemq-denial-of-service

    Post summary

    Apache ActiveMQ is vulnerable to a denial‑of‑service attack via an out‑of‑memory condition (CVE‑2026‑39304); no exploit code or active exploitation is reported, but administrators should limit resources and restrict network access.

    0000076
    12 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-39304 🚨 Risk Level: Unknown 🧩 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39304 #CVE-2026-39304 #CVE #Apache #CyberSecurity #InfoSec https://t.co/3CKM97FYOb

    Post summary

    The tweet announces a newly identified CVE-2026-39304 affecting Apache, links to the NVD entry, and notes an unknown risk level, providing no further technical or exploit details.

    0000035
    125 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---

Explore more