SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-75880

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis are vulnerable to a denial of service attack caused by an authenticated client attaching a consumer with a specially crafted wildcard selector, leading to excessive evaluation and resource exhaustion on shared broker threads. Organizations using versions 2.50.0 through 2.56.0 of Apache Artemis or 1.0.0 through 2.44.0 of ActiveMQ Artemis should prioritize upgrading to version 2.57.0 to mitigate this risk.

CVE
CVE-2026-75880
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
Apache

Original NVD Description

An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes this issue.