{"id":"BIT-activemq-2026-50750","summary":"Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270","details":"Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All.\n\nFollowing the fix for  CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an repeated BrokerInfo commands without sending a ConnectionInfo, until the broker will crash with OOM.\nThis issue affects Apache ActiveMQ Broker: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7; Apache ActiveMQ All: from 5.19.7 before 5.19.8, from 6.2.6 before 6.2.7.\n\nUsers are recommended to upgrade to version 6.2.7, which fixes the issue.","aliases":["CVE-2026-50750"],"modified":"2026-09-08T08:45:09.666689832Z","published":"2026-07-06T05:47:14.523Z","database_specific":{"cpes":["cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:*"],"severity":"High"},"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/nhkmbdym61yp6wwy0dny8w1p46sm87kr"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50750"}],"affected":[{"package":{"name":"activemq","ecosystem":"Bitnami","purl":"pkg:bitnami/activemq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.19.7"},{"fixed":"5.19.8"},{"introduced":"6.2.6"},{"fixed":"6.2.7"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/activemq/BIT-activemq-2026-50750.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}],"schema_version":"1.9.0"}