High [CVE-2026-39304] Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
This high-severity Apache Software Foundation advisory covers CVE-2026-39304 affecting Apache ActiveMQ, Apache ActiveMQ Client, Apache ActiveMQ Broker.
Android app · Google Play
Monitor future Apache Software Foundation CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients.
This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS. Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM.
Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.
This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.
Affected products named by the advisory: Apache ActiveMQ All.
- Apache ActiveMQ Client before 5.19.4
- Apache ActiveMQ Client 6.0.0 before 6.2.4
- Apache ActiveMQ Broker before 5.19.4
- Apache ActiveMQ Broker 6.0.0 before 6.2.4
- Apache ActiveMQ All before 5.19.4
- Apache ActiveMQ All 6.0.0 before 6.2.4
- Apache ActiveMQ before 5.19.4
- Apache ActiveMQ 6.0.0 before 6.2.4
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
- 5.19.4
- 6.2.4
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Mitigation checklist
- Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.
Official advisory · high-confidence parse· fetched 1 month ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.