CVE-2026-49362
- EPSS 0.42%
- Veröffentlicht 10.09.2026 04:56:19
- Zuletzt bearbeitet 16.09.2026 01:10:42
An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Ac...
CVE-2026-49363
- EPSS 0.4%
- Veröffentlicht 10.09.2026 04:51:56
- Zuletzt bearbeitet 16.09.2026 01:10:36
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ ...
CVE-2026-49364
- EPSS 0.29%
- Veröffentlicht 10.09.2026 04:49:27
- Zuletzt bearbeitet 16.09.2026 01:10:31
An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis...
CVE-2026-57822
- EPSS 0.34%
- Veröffentlicht 10.09.2026 04:46:52
- Zuletzt bearbeitet 16.09.2026 01:10:26
When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of cer...
CVE-2026-57967
- EPSS 0.55%
- Veröffentlicht 10.09.2026 04:43:10
- Zuletzt bearbeitet 16.09.2026 01:10:22
An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; ...
CVE-2026-67593
- EPSS 0.46%
- Veröffentlicht 10.09.2026 04:40:29
- Zuletzt bearbeitet 16.09.2026 01:10:17
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemi...
CVE-2026-75880
- EPSS 0.29%
- Veröffentlicht 10.09.2026 04:36:08
- Zuletzt bearbeitet 18.09.2026 15:17:11
An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue af...
CVE-2026-40914
- EPSS 0.37%
- Veröffentlicht 28.05.2026 12:28:25
- Zuletzt bearbeitet 15.06.2026 13:03:40
A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routing-type supported by that address even if said user...
CVE-2026-32642
- EPSS 0.42%
- Veröffentlicht 24.03.2026 08:16:01
- Zuletzt bearbeitet 15.06.2026 13:03:40
Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable JMS topic subscription on an address that doesn't exist with an authent...
CVE-2026-4649
- EPSS 0.33%
- Veröffentlicht 24.03.2026 08:15:16
- Zuletzt bearbeitet 24.03.2026 15:53:48
Apache Artemis before version 2.52.0 is affected by an authentication bypass flaw which allows reading all messages exchanged via the broker and injection of new message ( CVE-2026-27446 https://www.cve.org/CVERecord ). Since KNIME Business Hub uses ...