Input validation error in ActiveMQ - CVE-2026-49432
Published: July 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the STOMP connector when processing STOMP frames with a negative content-length. A remote attacker can send a specially crafted STOMP frame to cause a denial of service.
For the NIO STOMP transport, exploitation can grow the per-connection command buffer beyond configured limits and lead to out-of-memory conditions. For the blocking STOMP protocol, exploitation causes abnormal transport exception handling for the affected connection and its closure.
Affected software
Jazz for Service Management
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-49432
Jazz for Service Management - update to 1.1.3.27 ifix 0002
activemq - update to 5.19.8-1
activemq-javadoc - update to 5.19.8-1