CVE-2026-49432Disclosure(apache / activemq)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by sending a negative content-length. For the NIO STOMP transport, an attacker can keep streaming body bytes and grow the per-connection command buffer beyond configured limits to cause OOM. For the blocking STOMP protocol, an error will instead force abnormal transport exception handling for the affected connection and closure. This issue affects Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ Stomp: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7 or 5.19.8, which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
activemq

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-30: 3Technical Details · 2026-06-30: 206-30
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-49432 Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP… https://www.cve.org/CVERecord?id=CVE-2026-49432

    Post summary

    The text discloses a new CVE-2026-49432 as an improper input validation flaw in Apache ActiveMQ that allows remote unauthenticated access to STOMP, but does not provide any PoC, exploit code, patch, or evidence of active exploitation.

    000201.0K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-49432 Denial of Service via Improper Input Validation in Apache... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-49432 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely cites CVE-2026-49432 and links to a vulnerability details page, providing no actionable information on exploitation, mitigation, or validation.

    0000083
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-49432 Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP… https://www.cve.org/CVERecord?id=CVE-2026-49432 ----- Traducción: CVE-2026-49432 Vul… http://infoflow.cloud`

    Post summary

    The post announces the existence of CVE‑2026‑49432, detailing it as an improper input validation issue affecting Apache ActiveMQ’s STOMP interface, without providing proof of exploitation or mitigation details.

    0000031
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---

Explore more