Skip to content
VulniPulse
High7.5Apache Software Foundation

High [CVE-2026-39304] Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM

This high-severity Apache Software Foundation advisory covers CVE-2026-39304 affecting Apache ActiveMQ, Apache ActiveMQ Client, Apache ActiveMQ Broker.

CVE-2026-39304 Published Apr 10, 2026Updated by vendor Jul 15, 2026
Affected products & platforms
Apache Software FoundationMessagingActiveMQ
Open vendor advisory

Android app · Google Play

Monitor future Apache Software Foundation CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by clients.

This makes it possible for a client to rapidly trigger updates which causes the broker to exhaust all its memory in the SSL engine leading to DoS. Note: TLS versions before TLSv1.3 (such as TLSv1.2) are broken but are not vulnerable to OOM.

Previous TLS versions require a full handshake renegotiation which causes a connection to hang but not OOM. This is fixed as well.

This issue affects Apache ActiveMQ Client: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.4; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.

Affected products named by the advisory: Apache ActiveMQ All.

Affected versions
  • Apache ActiveMQ Client before 5.19.4
  • Apache ActiveMQ Client 6.0.0 before 6.2.4
  • Apache ActiveMQ Broker before 5.19.4
  • Apache ActiveMQ Broker 6.0.0 before 6.2.4
  • Apache ActiveMQ All before 5.19.4
  • Apache ActiveMQ All 6.0.0 before 6.2.4
  • Apache ActiveMQ before 5.19.4
  • Apache ActiveMQ 6.0.0 before 6.2.4

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Fixed versions
  • 5.19.4
  • 6.2.4

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Users are recommended to upgrade to version 6.2.4 or 5.19.5, which fixes the issue.

Official advisory · high-confidence parse· fetched 1 month ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.