Skip to main content

Vendor/product archive

apache / artemis CVEs

Beta · best-effort

15 CVEs tagged to apache / artemis1 Critical, 6 High, 6 Medium, 2 Low, 0 Unrated.

CVE-2026-40914

Published May 28, 2026

A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address c…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-32642

Published Mar 24, 2026

Incorrect Authorization (CWE-863) vulnerability in Apache Artemis, Apache ActiveMQ Artemis exists when an application using the OpenWire protocol attempts to create a non-durable…

CVSS 2.3 · Low
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-27446

Published Mar 4, 2026

Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to fo…

CVSS 9.3 · Critical
evidence mentions
13
Buzz score
42.4
Vendor/product tagsBeta · best-effort

CVE-2025-27391

Published Apr 9, 2025

Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-27427

Published Apr 1, 2025

A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type support…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-50780

Published Oct 14, 2024

Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-4040

Published Aug 24, 2022

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26117

Published Jan 27, 2021

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache…

CVSS 7.5 · High

CVE-2020-13932

Published Jul 20, 2020

In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially crafted MQTT packet which has an XSS payload as client-id or topic name can exploit this vulnerability. The XSS payload is…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-15 of 15 CVEsPage 1 of 1