Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation. | |
| Title | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization | |
| First Time appeared |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| Weaknesses | CWE-470 | |
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:jboss_enterprise_application_platform:7 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T13:10:33.668Z
Reserved: 2026-09-28T12:37:20.491Z
Link: CVE-2026-101292
Updated: 2026-09-28T13:10:30.466Z
Status : Received
Published: 2026-09-28T13:17:21.267
Modified: 2026-09-28T14:17:14.497
Link: CVE-2026-101292
No data.
OpenCVE Enrichment
No data.