Red Hat AMQ Broker
38 known vulnerabilities in Red Hat AMQ Broker, 2 critical, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-34197 CVSS 8.8 high · actively exploited Apache ActiveMQ Improper Input Validation Vulnerability
Latest vulnerabilities
- CVE-2026-101292 CVSS 8.2 high Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy()…
- CVE-2026-93574 CVSS 6.5 medium A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially…
- CVE-2026-93562 CVSS 6.5 medium A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to…
- CVE-2026-93579 CVSS 6.5 medium A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line…
- CVE-2026-93573 CVSS 6.5 medium A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation…
- CVE-2026-93569 CVSS 8.2 high A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process…
- CVE-2026-93568 CVSS 7.5 high A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended…
- CVE-2026-93567 CVSS 7.5 high A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host…
- CVE-2026-93566 CVSS 6.5 medium A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control…
- CVE-2026-93565 CVSS 7.5 high A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens…
- CVE-2026-93564 CVSS 7.5 high A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to…
- CVE-2026-93558 CVSS 7.5 high A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using…
- CVE-2026-93492 CVSS 5.3 medium A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large…
- CVE-2026-93491 CVSS 7.5 high A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1…
- CVE-2026-93488 CVSS 7.5 high A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because…
- CVE-2026-93575 CVSS 7.5 high A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted…
- CVE-2026-86404 CVSS 8.8 high EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses…
- CVE-2026-84218 CVSS 8.1 high A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a…
- CVE-2026-13676 CVSS 7.5 high fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path…
- CVE-2026-54513 CVSS 8.1 high jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until…
- CVE-2026-48779 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to…
- CVE-2026-12143 CVSS 8.7 high form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to…
- CVE-2026-44496 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the…
- CVE-2026-44495 CVSS 7.7 high Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains…
- CVE-2026-44494 CVSS 8.7 high Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a…
- CVE-2026-44492 CVSS 8.6 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise IPv4-mapped IPv6…
- CVE-2026-44488 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request…
- CVE-2026-44487 CVSS 8.2 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a…
- CVE-2026-44486 CVSS 7.5 high Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy…
- CVE-2026-45736 CVSS 7.5 high ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to…