Cross-site scripting in ActiveMQ - CVE-2026-42253

 

Cross-site scripting in ActiveMQ - CVE-2026-42253

Published: June 4, 2026


Vulnerability identifier: #VU133394
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-42253
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject or overwrite HTTP response headers.

The vulnerability exists due to improper neutralization of input during web page generation in the MessageServlet in the ActiveMQ web console API when copying JMS message properties into HTTP response headers. A remote attacker can set crafted JMS message properties to inject or overwrite HTTP response headers.

The issue affects messages returned by the servlet.


Affected software

ActiveMQ
openEuler
activemq
activemq-javadoc

How to mitigate CVE-2026-42253

Install security update from vendor's website.

ActiveMQ - addressed in versions 5.19.7, 6.2.6
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1

External References

Related Security Bulletins