Input validation error in ActiveMQ - CVE-2026-59878
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the AMQP NIO connector when processing a crafted frame size value. A remote attacker can send a specially crafted frame to cause a denial of service.
If triggered rapidly enough, the issue can exhaust the NIO thread pool and deny service to other connections.
Affected software
openEuler
activemq
activemq-javadoc
How to mitigate CVE-2026-59878
activemq - update to 5.19.9-1
activemq-javadoc - update to 5.19.9-1