Deserialization of Untrusted Data in Apache ActiveMQ Artemis and Apache Artemis - CVE-2026-57822
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to deserialization of untrusted data in message-based management parameter processing when processing message-based management requests. A remote privileged user can send a crafted management request containing parameters that cause excessive computation and pin a processing thread to cause a denial of service.
Exploitation requires MANAGE permission to perform management-via-messaging.
Affected software
Apache Artemis