Cross-site scripting in ActiveMQ - CVE-2026-42253
Published: June 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject or overwrite HTTP response headers.
The vulnerability exists due to improper neutralization of input during web page generation in the MessageServlet in the ActiveMQ web console API when copying JMS message properties into HTTP response headers. A remote attacker can set crafted JMS message properties to inject or overwrite HTTP response headers.
The issue affects messages returned by the servlet.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-42253
activemq - update to 5.19.7-1
activemq-javadoc - update to 5.19.7-1