logo

Apache ActiveMQ Patches “OOM” and MQTT Protocol Flaws

ID: 6166557c-fae2-53cb-9dac-d9a861d004f8

STIX ID: report--6166557c-fae2-53cb-9dac-d9a861d004f8

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-04-13

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache ActiveMQ issued critical updates for multiple vulnerabilities: CVE-2026-39304 (Important) enables a malicious TLSv1.3 client to force frequent KeyUpdate processing and exhaust broker memory causing an OOM DoS, and CVE-2026-40046 represents a regression that reintroduced an MQTT integer overflow; administrators are advised to upgrade 6.x to 6.2.4+ and 5.x to 5.19.5+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.