Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation. | |
| Title | Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization | |
| First Time appeared |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| Weaknesses | CWE-470 | |
| CPEs | cpe:/a:redhat:amq_broker:7 cpe:/a:redhat:jboss_enterprise_application_platform:7 |
|
| Vendors & Products |
Redhat
Redhat amq Broker Redhat jboss Enterprise Application Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T13:10:33.668Z
Reserved: 2026-09-28T12:37:20.491Z
Link: CVE-2026-101292
Updated: 2026-09-28T13:10:30.466Z
Status : Received
Published: 2026-09-28T13:17:21.267
Modified: 2026-09-28T14:17:14.497
Link: CVE-2026-101292
No data.
OpenCVE Enrichment
No data.