CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6926

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service

CVE-2026-75880 affects Apache Artemis and Apache ActiveMQ Artemis, where an authenticated client can craft a message selector with wildcards to trigger excessive evaluation during message delivery. This consumption of broker resources on a shared thread can cause denial of service. The vulnerability affects Artemis versions 2.50.0 through 2.56.0 and ActiveMQ Artemis versions 1.0.0 through 2.44.0.

Why it matters: Organizations running vulnerable versions of Artemis or ActiveMQ Artemis need to upgrade immediately, as authenticated users can disable message broker availability without requiring exploit code or external access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary