Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilitypatch-regression

Apache ActiveMQ Flaws Enable Path Traversal and TLS DoS

Updated 2mo agoFirst seen Apr 6, 20262 sources

Apache disclosed two vulnerabilities affecting multiple ActiveMQ components, including Client, Broker, and bundled distributions. CVE-2026-33227 is a low-severity pathname restriction flaw that lets an authenticated user manipulate a supplied key value to traverse the classpath in two cases: when creating a STOMP consumer and when browsing messages through the web console. Apache warned the issue could expose classpath resource loading and potentially be chained with another attack. The flaw affects the 5.x branch before 5.19.3 and the 6.x branch from 6.0.0 before 6.2.2, but Apache said those initial fixes were incomplete on Windows because of path separator handling, and recommended upgrading instead to 5.19.4 or 6.2.3.

Apache also published CVE-2026-39304, an important denial-of-service flaw in ActiveMQ's NIO SSL transports caused by incorrect handling of TLS 1.3 KeyUpdate messages. A client can repeatedly trigger updates and exhaust broker memory in the SSL engine, causing out-of-memory crashes and service disruption. Apache added that related handshake handling is also broken for earlier TLS versions such as TLS 1.2, though those cases lead to hung connections rather than memory exhaustion. The DoS issue affects the 5.x branch before 5.19.4 and the 6.x branch from 6.0.0 before 6.2.4; users are advised to upgrade to 5.19.5 or 6.2.4.

Share:
Apache ActiveMQ Flaws Enable Path Traversal and TLS DoS
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 9, 20262mo ago

Apache releases upgrade guidance for CVE-2026-39304

Apache said the flaw affects the 5.x branch before 5.19.4 and the 6.x branch from 6.0.0 before 6.2.4, and advised users to upgrade to 5.19.5 or 6.2.4. Apache also noted related TLS handshake handling problems in earlier TLS versions can cause connection hangs rather than out-of-memory conditions.

Apache discloses CVE-2026-39304 ActiveMQ TLS KeyUpdate DoS flaw

Apache disclosed CVE-2026-39304, an important denial-of-service vulnerability in ActiveMQ NIO SSL transports. A client can abuse TLS 1.3 KeyUpdate handling to exhaust broker memory and trigger out-of-memory service disruption.

Apr 6, 20263mo ago

Apache recommends newer ActiveMQ fixes for CVE-2026-33227

Apache said affected versions include the 5.x branch before 5.19.3 and the 6.x branch from 6.0.0 before 6.2.2, but advised upgrading to 5.19.4 or 6.2.3 because the earlier fixes were incomplete on Windows due to a path separator bug. Dawei Wang was credited with discovering the vulnerability.

Apache discloses CVE-2026-33227 in ActiveMQ

Apache disclosed CVE-2026-33227, a low-severity path traversal-style flaw affecting multiple Apache ActiveMQ components. The issue allows an authenticated user-supplied key value to traverse the classpath in STOMP consumer creation and web console message browsing scenarios.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Affected products
1 linked
Apache-Activemq
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.